5.3

CVSS3.1

CVE-2026-35345 - uutils coreutils tail Privileged Information Disclosure via Symlink Replacement Race

A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. Unlike GNU tail, the uutils implementation continues to monitor a path after it has been replaced by a symbolic link, subsequently outputting the conteโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 27, 2026, 7:54 p.m.

3.3

CVSS3.1

CVE-2026-35344 - uutils coreutils dd Silent Data Corruption via Unconditional Truncation Error Suppression

The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result::ok() on truncation attempts. While intended to mimic GNU behavior for special files like /dev/null, the uutils implementation also hides failures on regular files and directorieโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 27, 2026, 7:54 p.m.

3.3

CVSS3.1

CVE-2026-35343 - uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters

The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim function, causing the utility to print non-delimited lines tโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 27, 2026, 7:54 p.m.

3.3

CVSS3.1

CVE-2026-35342 - uutils coreutils mktemp Insecure Temporary File Placement via Empty TMPDIR

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the curreโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 27, 2026, 7:54 p.m.

7.1

CVSS3.1

CVE-2026-35341 - uutils coreutils mkfifo Unauthorized Permission Change on Existing Files

A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a file already exists at the target path, it fails to terminate the operation for that path and continues to execute a follow-up set_permiโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 7:05 p.m.

5.5

CVSS3.1

CVE-2026-35340 - uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode

A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The final exit code is determined only by the last file processed. If the last operation succeeds, the command returns 0 even if earlier ownership โ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

5.5

CVSS3.1

CVE-2026-35339 - uutils coreutils chmod False Success Exit Code in Recursive Mode

The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the success or failure of the last file processed. This allows the command to return an exit code of 0 (success) even if errโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 27, 2026, 7:54 p.m.

7.3

CVSS3.1

CVE-2026-35338 - uutils coreutils chmod Path Traversal Bypass of --preserve-root

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolicโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:07 p.m. ๐Ÿ”„ Last Modified: April 27, 2026, 12:28 p.m.

6.5

CVSS3.1

CVE-2025-0186 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests tโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:05 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 8:51 p.m.

6.5

CVSS3.1

CVE-2025-3922 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resourโ€ฆ

๐Ÿ“… Published: April 22, 2026, 4:05 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 8:50 p.m.
Total resulsts: 347008
Page 105 of 34,701
ยซ previous page ยป next page
Filters