CVE detail
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 11.1
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
36 source links · newest first
- The Convergence of Cloud Secrets & AI RiskSentinelOne Labs
initial access points. The top verified exploit paths continue to involve older, critical CVEs, including: Shellshock ( CVE-2014-6271 ) FortiGate SSL VPN credential disclosure ( CVE-2018-13379 ) Pulse Secure VPN arbitrary file read ( CVE-2019-11510 ) Webmin RCE ( CVE-2019-15107 ) Barracuda ESG zero-day backdoor ( CVE-2023-1698 ) Since these vulnerabil
vendorwww.sentinelone.comMay 13, 2026, 6:11 PM RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, CCTV systems, and servers, active globally since June. Trend Micro researchers reported that the RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, NVRs, CCTV systems, and web servers, active globally since June. Experts noted that the latest […]
newssecurityaffairs.comOct 10, 2025, 7:33 AM- U.S. CISA adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these […]
newssecurityaffairs.comOct 4, 2025, 3:49 PM - Old vulnerabilities are still a big problemHelp Net Security
A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →
newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week announced the addition of eight more vulnerabilities to the list of security flaws known to be exploited in malicious attacks.
newswww.securityweek.comFeb 1, 2022, 11:12 AMThe US CISA added eight more flaws to its Known Exploited Vulnerabilities Catalog that are known to be used in attacks in the wild. The US Cybersecurity & Infrastructure Security Agency (CISA) has added eight more flaws to the Known Exploited Vulnerabilities Catalog. The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that […]
newssecurityaffairs.comJan 31, 2022, 9:05 PMOrganizations in the financial and insurance sectors were the most targeted by threat actors in 2020, continuing a trend that was first observed roughly five years ago, IBM Security reports.
newswww.securityweek.comApr 2, 2021, 12:42 PM- Three major gaps in the Cyberspace Solarium Commission’s report that need to be addressedHelp Net Security
Released in March 2020, the Cyberspace Solarium Commission’s report urges for the U.S. government and private sector to adopt a “new, strategic approach to cybersecurity,” namely layered cyber deterrence. Among the Commission’s lengthy 182-page report’s recommendations are that security vendors must be responsible for providing security updates for their products or services as long as they are providing usability updates and bug fixes. Additionally, the report calls for Congress to “pass a law establishing that … More →
newswww.helpnetsecurity.comJul 9, 2020, 4:30 AM Crooks are attempting to exploit a recently patched Drupal vulnerability, tracked as CVE-2018-7602, to drop Monero mining malware onto vulnerable systems. The CVE-2018-7602 flaw is a highly critical remote code execution issue, also known as Drupalgeddon3, that was addressed by the Drupal team in April with the release of versions 7.59, 8.4.8 and 8.5.3. The security patch for the […]
newssecurityaffairs.comJun 22, 2018, 5:19 PM- Hackers Exploit Drupal Flaw for Monero MiningSecurityWeek
Network attacks exploiting a recently patched Drupal vulnerability are attempting to drop Monero mining malware onto vulnerable systems, Trend Micro reports.
newswww.securityweek.comJun 22, 2018, 12:21 PM - Rudimentary attacks pose the greatest risk to midsized organizationsHelp Net Security
Rudimentary attacks, such as intrusion attempts, information gathering, and policy violations pose the greatest risk to midsized organizations, according to eSentire. Attacks per type heat map “In 2016, the eSentire SOC detected almost 5 million attacks across hundreds of primarily small to medium organizations, spanning multiple industries,” said Viktors Engelbrehts, director of threat intelligence at eSentire. “Cybercriminals are attracted to easy targets because they are low risk, high reward, and require little effort to execute. … More →
newswww.helpnetsecurity.comMay 8, 2017, 12:55 PM - Shellshock Attacks Still Cheap and Easy: IBMSecurityWeek
Two and a half years after being discovered, the Shellshock vulnerability continues to be abused in attacks, and for a good reason: it is a very cheap and easy attack, IBM says.
newswww.securityweek.comMar 6, 2017, 6:13 PM - Top Cybersecurity Headlines of 2014SecurityWeek
Data breaches, dangerous vulnerabilities and more dominated the headlines this year in cybersecurity.
newswww.securityweek.comDec 30, 2014, 10:10 PM - Attackers shellshock, take over devices running on BusyBoxHelp Net Security
ShellShock, the remote code execution bug (CVE-2014-6271) affecting GNU Bash, the command interpreter present on many Unix systems and Linux distributions, is still being exploited by attackers. Trend Micro threat response engineer Rhena Inocencio warns about attackers leveraging a new version of the Bashlite malware, which was initially created as a DDoS bot with brute forcing capabilities and exploits the ShellShock bug. The malware now targets both computers and other devices running on BusyBox, located … More →
newswww.helpnetsecurity.comNov 17, 2014, 11:30 AM It appears that 2014 will be remembered in the IT industry for several severe and wide-reaching server-side vulnerabilities. In April, a serious flaw ( CVE-2014-0160 ) in the widely-used OpenSSL encryption software that protects website traffic shook the industry (a.k.a. Heartbleed), leaving hundreds of thousands of systems open to attacks from cybercriminals. More than six months later, thousands of websites and devices still remain vulnerable . In September, multiple critical vulnerabilities ( CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE 2014-6278 ) were reported in the GNU Bourne-Again Shell (Bash), the common command-line shell used in many Linux / UNIX operating systems and Apple’s Mac OS X. The flaws could allow an attacker to remotely execute shell commands by attaching malicious code in environment variables used by the operating system. Similar to Heartbleed, these flaws affect a broad range of systems, including but not limited to Apache…
newswww.securityweek.comNov 5, 2014, 3:18 PMThe GNU Bash vulnerability dubbed ShellShock affects a wide range of software solutions, including some industrial products developed by the German engineering and electronics giant Siemens.
newswww.securityweek.comOct 8, 2014, 6:47 PM- Bash bug and risks posed by incomplete patches, discovered other two additional bugsSecurity Affairs
The security researcher Michal Zalewski revealed the details of other two additional bugs he discovered in the Bourne Again Shell after the Bash Bug case. IT community worldwide has been shocked by the discovery of the Bash Bug flaw, a vulnerability that was present in the popular Bash component for more than two decades. While principal […]
newssecurityaffairs.comOct 5, 2014, 1:28 PM Joining several major tech companies, VMware has started rolling out software updates that address the recently discovered GNU Bash vulnerability dubbed ShellShock.
newswww.securityweek.comOct 2, 2014, 1:41 PMResearchers have discovered hackers trying to exploit the Shellshock Bash vulnerability to compromise network attached storage devices in universities in the U.S., Japan and Korea. The attackers were taking advantage of a publicly disclosed security weakness in which the web servers embedded in the devices manufactured by QNAP have administrative privileges by default, researchers for […]
newswww.csoonline.comOct 1, 2014, 11:43 PMEver since the existence of the GNU Bash flaw ( Shellshock ) came to light last week, threat actors have been searching for vulnerable machines that they can exploit for various purposes, Incapsula said on Monday.
newswww.securityweek.comSep 30, 2014, 9:42 AM- Apple patches Shellshock bug in OS XHelp Net Security
Apple has finally released a security update for OS X that will close up the critical remote code execution Shellshock bug found in the GNU Bash UNIX shell. The update resolves both the CVE-2014-6271 issue discovered by Stephane Chazelas, as well as the CVE-2014-7169 one flagged by Tavis Ormandy. Security updates have been provided for OS X Mavericks, Mountain Lion, and Lion users. According to Ars Technica, the patch will not be provided for current … More →
newswww.helpnetsecurity.comSep 30, 2014, 4:54 AM The number of attempts by hackers to compromise computers through the Shellshock vulnerability is rising, but companies have options for defending against attackers. Shellshock is the name given to a set of at least six vulnerabilities in GNU Bash, the default command shell found in Linux, Unix and Mac OS X. The flaws in Bash, […]
newswww.csoonline.comSep 30, 2014, 12:58 AMSeveral organizations that use the GNU Bourne Again Shell (Bash) in their products have been hard at work producing software updates to address the recently discovered vulnerability dubbed “ Shellshock ” or “Bash Bug.” GNU Bash is a command-line shell used in Linux, Unix and Mac OS X operating systems which is installed not only on personal computers and servers, but also installed on other connected “Internet of Things” (IoT) devices. The vulnerability ( CVE-2014-6271 ) affects version 1.14 and later of the shell and can be exploited to execute arbitrary commands and take over affected machines. Red Hat published a security update shortly after the existence of Shellshock came to light. However, it soon became clear that the fix had been incomplete since, according to Red Hat, “Bash still allowed certain characters to be injected into other environments via specially crafted environment variables.” This second issue has been assigned CVE-2014-7169 . On Friday, both Red Hat and Fedora…
newswww.securityweek.comSep 29, 2014, 11:22 AMFrom Thursday on, several security firms reported a drastic uptick in the number of attacks that leverage the recently disclosed vulnerability in GNU Bash (CVE-2014-6271), widely known as Shellshock. On Friday, AlienVault labs reported that the flaw was being used by two attackers to install two different pieces of malware on the victim system. One […]
newswww.csoonline.comSep 29, 2014, 11:00 AM- ShellShock could be used to hack VoIP systemsSecurity Affairs
Jaime Blasco at AlienVault Labs explained that ShellShock vulnerability could be exploited to hack Voice over IP systems worldwide. The Shellshock Bash is monopolizing the debate on the Internet security in these days, every vendor is assessing its product to verify the impact of the critical vulnerability Bash Bug (CVE-2014-6271). Apple recently announced that its Mac OS X based […]
newssecurityaffairs.comSep 28, 2014, 11:52 AM The existence of a highly critical vulnerability affecting the GNU Bourne Again Shell (Bash) has been brought to light this week. The security flaw is considered by some members of the industry as being worse than the notorious Heartbleed bug.
newswww.securityweek.comSep 26, 2014, 5:12 PMThe recently disclosed “Bash Bug” or “Shellshock” vulnerability that affects most versions of Linux, Unix, and Mac OS X operating systems is the latest threat to set IT security teams scrambling to protect their systems.
newswww.securityweek.comSep 26, 2014, 11:56 AM- Bash “Shellshock” bug: Who needs to worry?Help Net Security
As expected, attackers have begun exploiting the GNU Bash “Shellshock” remote code execution bug (CVE-2014-6271) to compromise systems and infect them with malware. After the disclosure of its existence, Alien Vault has begun running a new module in their honeypots and waiting for attackers aiming to exploit this vulnerability. “We have had several hits in the last 24 hours. Most of them are systems trying to detect if the system is vulnerable and they simple … More →
newswww.helpnetsecurity.comSep 26, 2014, 8:49 AM - Hackers target Bash Bug vulnerability in the wildSecurity Affairs
The critical vulnerability Bash Bug in common GNU shell could be exploited by botmaster to infect a huge number of machines on a large scale. The recently discovered Bash Bug vulnerability, coded as CVE-2014-6271 and known also as “Shellshock,” is worrying the security community due to its impact on a large-scale. The remotely exploitable critical flaw affects Linux, Unix and […]
newssecurityaffairs.comSep 26, 2014, 6:00 AM - Bash ‘Shellshock’ Vulnerability Under AttackSecurityWeek
Beating back the recently disclosed GNU Bourne Again Shell (Bash) vulnerability may not be as easy as some hoped.
newswww.securityweek.comSep 25, 2014, 11:09 PM Around 6:00 am PST on September 24, the details of a vulnerability in the widely used Bourne Again Shell (Bash) were disclosed by multiple Linux vendors. The vulnerability, assigned CVE-2014-6271 by Mitre, was originally discovered by Stephane Chazelas, a Unix and Linux network and telecom administrator and IT manager at UK robotics company SeeByte, Ltd.
vendorunit42.paloaltonetworks.comSep 25, 2014, 2:32 PM- Bash Bug is a critical risk to entire Internet infrastructureSecurity Affairs
Bash Bug is a critical flaw remotely Exploitable which affects Linux, Unix and Apple Mac OS X and that is threatening the global Internet infrastructure. A new critical vulnerability dubbed Bash Bug in Linux and Unix command-line shell, aka the GNU Bourne Again Shell, is threatening the IT world. The flaw, coded as CVE-2014-6271, is remotely exploitable and affects Linux […]
newssecurityaffairs.comSep 25, 2014, 9:38 AM - Critical Bash bug opens Unix, Linux, OS X systems to attacksHelp Net Security
The Bash “shellshock” flaw (CVE-2014-6271) was discovered last week by Unix/Linux specialist Stephane Chazelas, and its existence was made public on Wednesday. It affects Bash, the command interpreter present on many Unix systems and systems based on it: various Linux distributions and Apple’s OS X. It can be exploited by attackers looking to override or bypass environment restrictions to execute shell commands, i.e. unauthorized, malicious code. The flaw is deemed critical for many reasons. For … More →
newswww.helpnetsecurity.comSep 25, 2014, 8:20 AM A vulnerability (CVE-2014-6271) has been discovered in the GNU Bourne Again Shell (bash) that can be exploited to execute code.
newswww.securityweek.comSep 24, 2014, 11:24 PM- New bash bug could wreak havoc on Linux and OS X systemsMalwarebytes Labs
Update (12:34 PM): Web security firm Sucuri has already detected in the wild attempts to load remote shells onto servers using…
newswww.malwarebytes.comSep 24, 2014, 5:00 PM A remotely exploitable vulnerability has been discovered by Stephane Chazelas in bash on Linux and it is unpleasant. The vulnerability has the CVE identifier CVE-2014-6271 and has been given the name Shellshock by some. This affects Debian as well as other Linux distributions. You will need to patch ASAP. Bash supports exporting shell variables as well […]
newswww.csoonline.comSep 24, 2014, 3:35 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.99 · max 1 stars
- im2sinister/CVE-2014-6271High confidencegithubRepository topic discovery1 starsDiscovered Jul 15, 2026, 4:51 AM
- TheRealCiscoo/shellshock-manual-exploitationHigh confidencegithubRepository topic discovery1 starsDiscovered Jul 12, 2026, 4:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2014-7169CVSS 9.8 · Critical
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wr…
- CVE-2015-5165CVSS 9.3 · Critical
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecifi…
- CVE-2015-2590CVSS 9.8 · Critical
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability…
KEV listed6 mentions - CVE-2015-3209CVSS 7.5 · High
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted p…
- CVE-2020-25717CVSS 8.1 · High
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
- CVE-2021-4034CVSS 7.8 · High
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pr…