Toybox is a lightweight Unix command-line toolkit designed as a minimalist alternative to traditional GNU utilities, with a focus on embedded systems and resource-constrained environments. The observed vulnerability surface centers on the core Toybox implementation and manifests through NULL pointer dereference conditions, a weakness class typical of low-level command processors handling diverse input streams.
The number and severity of CVEs published that impact products developed by Toybox Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32298HIGH Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lead to a Denial of Service (DoS) via unspecified vectors. | Jul 14, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toybox Project.
Media articles that mention a CVE ID that affects a product developed by Toybox Project — matched by CVE ID, not by vendor name.