Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.16%—Uutils Coreutils22/4/202617/6/2026
A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The final exit code is determined only by the last file processed. If the last operation succeeds, the command returns 0 even if earlier ownership or group changes…
AnalizadaMedia (5.5)0.16%—Uutils Coreutils22/4/202617/6/2026
The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the success or failure of the last file processed. This allows the command to return an exit code of 0 (success) even if errors were encountered…
AnalizadaAlta (7.3)0.20%—Uutils Coreutils22/4/202617/6/2026
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute…
AplazadaMedia (4.4)0.29%—GNU CoreutilsAI27/5/202528/9/2026
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.
ModificadaMedia (5.5)0.49%💥 PoCGNU Coreutils6/2/202417/6/2026
A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.
ModificadaCrítica (9.8)2.3%—GNU Coreutils24/1/202017/6/2026
Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.
ModificadaAlta (7.8)0.52%—GNU Coreutils24/1/202017/6/2026
The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have…
ModificadaAlta (7.1)0.34%—GNU Coreutils4/1/201817/6/2026
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
ModificadaMedia (5.1)0.26%—GNU Coreutils20/9/201717/6/2026
fts.c in coreutils 8.4 allows local users to delete arbitrary files.
ModificadaMedia (4.6)0.43%—GNU Coreutils7/2/201717/6/2026
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
ModificadaAlta (7.5)7.1%—GNU CoreutilsCanonical Ubuntu Linux16/1/201517/6/2026
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
ModificadaMedia (6.9)0.36%—Selinuxproject Policycoreutils8/5/201417/6/2026
seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getresuid saved set-user-ID value, which makes it easier for local users to gain privileges by leveraging a program that mistakenly expected…
ModificadaMedia (6.9)0.37%—Redhat PolicycoreutilsRedhat Enterprise LinuxRedhat Fedora24/2/201116/6/2026
The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new…
ModificadaMedia (4.4)0.38%—Canonical Ubuntu LinuxGNU CoreutilsFedoraproject Fedora11/12/200916/6/2026
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
ModificadaMedia (4.4)0.31%—GNU Coreutils28/7/200816/6/2026
The default configuration of su in /etc/pam.d/su in GNU coreutils 5.2.1 allows local users to gain the privileges of a (1) locked or (2) expired account by entering the account name on the command line, related to improper use of the pam_succeed_if.so module.
ModificadaBaja (3.7)0.28%—GNU Coreutils2/5/200516/6/2026
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.
Orbitaley — Vulnerabilidades