Vendor
BusyBox AWK Vulnerability Leads to Denial of Service
1 TTP 1 CVEA stack overflow vulnerability, identified as CVE-2026-38752, exists in the evaluate() function within the AWK editor (editors/awk.c) of BusyBox commit 371fe9, which allows attackers to trigger a Denial of Service (DoS) condition by providing a specially crafted AWK script.
CVE-2026-38754: Busybox Heap Overflow Leads to Denial of Service
1 TTP 3 CVEsA heap overflow vulnerability (CVE-2026-38754) exists in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0. This flaw allows attackers to trigger a Denial of Service (DoS) by providing a specially crafted input, leading to application instability or unavailability.
BusyBox Vulnerability Allows Remote Code Execution or Denial-of-Service
2 rules 2 TTPsA vulnerability in BusyBox allows a remote attacker on an adjacent network to execute arbitrary code or cause a denial-of-service condition.
BusyBox DHCPv6 Client Heap Buffer Overflow Vulnerability (CVE-2026-29004)
2 rules 2 TTPs 1 CVEA heap buffer overflow vulnerability in BusyBox's DHCPv6 client allows network-adjacent attackers to trigger memory corruption, denial of service, or arbitrary code execution via crafted DHCPv6 responses.