3.3

CVSS3.1

CVE-2026-35342 - uutils coreutils mktemp Insecure Temporary File Placement via Empty TMPDIR

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the curre…

πŸ“… Published: April 22, 2026, 4:07 p.m. πŸ”„ Last Modified: May 4, 2026, 8:11 p.m.

7.1

CVSS3.1

CVE-2026-35341 - uutils coreutils mkfifo Unauthorized Permission Change on Existing Files

A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a file already exists at the target path, it fails to terminate the operation for that path and continues to execute a follow-up set_permi…

πŸ“… Published: April 22, 2026, 4:07 p.m. πŸ”„ Last Modified: April 24, 2026, 7:05 p.m.

5.5

CVSS3.1

CVE-2026-35340 - uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode

A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The final exit code is determined only by the last file processed. If the last operation succeeds, the command returns 0 even if earlier ownership …

πŸ“… Published: April 22, 2026, 4:07 p.m. πŸ”„ Last Modified: May 4, 2026, 8:12 p.m.

5.5

CVSS3.1

CVE-2026-35339 - uutils coreutils chmod False Success Exit Code in Recursive Mode

The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the success or failure of the last file processed. This allows the command to return an exit code of 0 (success) even if err…

πŸ“… Published: April 22, 2026, 4:07 p.m. πŸ”„ Last Modified: May 4, 2026, 8:14 p.m.

7.3

CVSS3.1

CVE-2026-35338 - uutils coreutils chmod Path Traversal Bypass of --preserve-root

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic…

πŸ“… Published: April 22, 2026, 4:07 p.m. πŸ”„ Last Modified: April 27, 2026, 12:28 p.m.

6.5

CVSS3.1

CVE-2025-0186 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests t…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:51 p.m.

6.5

CVSS3.1

CVE-2025-3922 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resour…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:50 p.m.

6.5

CVSS3.1

CVE-2025-6016 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain co…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:49 p.m.

2.7

CVSS3.1

CVE-2025-9957 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to imprope…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:46 p.m.

6.5

CVSS3.1

CVE-2026-1660 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation.

πŸ“… Published: April 22, 2026, 4:04 p.m. πŸ”„ Last Modified: April 23, 2026, 8:45 p.m.
Total resulsts: 348132
Page 216 of 34,814
Β« previous page Β» next page
Filters