CVE-2015-8212: Netbsd

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.

Affected products

  • Netbsd Netbsd: version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; version 6.0.5 only; …

Published 2017-01-19. Last modified 2026-06-17.