CVE detail
CVE-2014-6278
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- U.S. CISA adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these […]
newssecurityaffairs.comOct 4, 2025, 3:49 PM Patched in mid-May, the security defect allows remote unauthenticated attackers to execute arbitrary commands with root privileges.
newswww.securityweek.comOct 3, 2025, 10:44 AM- Top Cybersecurity Headlines of 2014SecurityWeek
Data breaches, dangerous vulnerabilities and more dominated the headlines this year in cybersecurity.
newswww.securityweek.comDec 30, 2014, 10:10 PM The GNU Bash vulnerability dubbed ShellShock affects a wide range of software solutions, including some industrial products developed by the German engineering and electronics giant Siemens.
newswww.securityweek.comOct 8, 2014, 6:47 PM- Bash bug and risks posed by incomplete patches, discovered other two additional bugsSecurity Affairs
The security researcher Michal Zalewski revealed the details of other two additional bugs he discovered in the Bourne Again Shell after the Bash Bug case. IT community worldwide has been shocked by the discovery of the Bash Bug flaw, a vulnerability that was present in the popular Bash component for more than two decades. While principal […]
newssecurityaffairs.comOct 5, 2014, 1:28 PM Joining several major tech companies, VMware has started rolling out software updates that address the recently discovered GNU Bash vulnerability dubbed ShellShock.
newswww.securityweek.comOct 2, 2014, 1:41 PMThe number of attempts by hackers to compromise computers through the Shellshock vulnerability is rising, but companies have options for defending against attackers. Shellshock is the name given to a set of at least six vulnerabilities in GNU Bash, the default command shell found in Linux, Unix and Mac OS X. The flaws in Bash, […]
newswww.csoonline.comSep 30, 2014, 12:58 AM- Bash Shellshock bug: More attacks, more patchesHelp Net Security
As vendors scramble to issue patches for the GNU Bash Shellshock bug and companies rush to implement them, attackers around the world are probing systems for the hole it opens. Initial attacks geared towards creating DDoS botnets managed via IRC have been followed by reconnaissance attempts in Brazil and China, where the IPs of various institutions (including financial) have been probed and, after found vulnerable to the bug, the attackers “asked” the target servers for … More →
newswww.helpnetsecurity.comSep 29, 2014, 11:17 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2016-0634CVSS 7.5 · High
The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
- CVE-2014-6277CVSS 10.0 · Critical
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cau…
- CVE-2014-7169CVSS 9.8 · Critical
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wr…
- CVE-2014-6271CVSS 9.8 · Critical
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cr…
- CVE-2026-12943CVSS 9.8 · Critical
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticate…
- CVE-2026-12940CVSS 9.8 · Critical
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launche…