CVE-2022-30065High· 7.8▾ TwilightA use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
1.2% → 1.3%
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
busybox = 1.35.0scalance_sc622-2c_firmware < 3.0scalance_sc626-2c_firmware < 3.0scalance_sc632-2c_firmware < 3.0scalance_sc636-2c_firmware < 3.0scalance_sc642-2c_firmware < 3.0scalance_sc646-2c_firmware < 3.0Upgrade past the affected range:
scalance_sc622-2c_firmware 3.0scalance_sc626-2c_firmware 3.0scalance_sc632-2c_firmware 3.0scalance_sc636-2c_firmware 3.0scalance_sc642-2c_firmware 3.0scalance_sc646-2c_firmware 3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-48174Critical· 9.8There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35
CVE-2022-1734High· 7.0A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.
CVE-2022-1011High· 7.8A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write()
CVE-2023-25747High· 7.5A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android
CVE-2022-26486Critical· 9.6An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape
CVE-2022-26485High· 8.8Removing an XSLT parameter during processing could have lead to an exploitable use-after-free