Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1280 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.7)0.21%—Uutils Coreutils22/4/202617/6/2026
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementation uses a path-string check rather than comparing device and inode numbers to identify the root directory. An attacker or accidental user can bypass this safeguard by using a symbolic link that…
AnalizadaMedia (5.5)0.14%—Uutils Coreutils22/4/202617/6/2026
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and utilizes expect(), causing an immediate crash when encountering valid but non-UTF-8 paths. This diverges from GNU sort,…
AnalizadaMedia (4.4)0.15%—Uutils Coreutils22/4/202617/6/2026
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both input paths to compare content without first verifying if the paths refer to regular files. If an input path is a FIFO or a…
AnalizadaBaja (3.3)0.17%—Uutils Coreutils22/4/202617/6/2026
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 byte sequences with the Unicode replacement character (U+FFFD). This behavior differs from GNU comm, which processes raw…
AnalizadaMedia (5.3)0.10%—Uutils Coreutils22/4/202617/6/2026
A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. Unlike GNU tail, the uutils implementation continues to monitor a path after it has been replaced by a symbolic link, subsequently outputting the contents of the link's…
AnalizadaBaja (3.3)0.13%—Uutils Coreutils22/4/202617/6/2026
The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result::ok() on truncation attempts. While intended to mimic GNU behavior for special files like /dev/null, the uutils implementation also hides failures on regular files and directories caused by full…
AnalizadaBaja (3.3)0.15%—Uutils Coreutils22/4/202617/6/2026
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim function, causing the utility to print non-delimited lines that should have been…
AnalizadaBaja (3.3)0.15%—Uutils Coreutils22/4/202617/6/2026
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory…
AnalizadaAlta (7.1)0.14%—Uutils Coreutils22/4/202617/6/2026
A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a file already exists at the target path, it fails to terminate the operation for that path and continues to execute a follow-up set_permissions call. This…
AnalizadaMedia (5.5)0.16%—Uutils Coreutils22/4/202617/6/2026
A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The final exit code is determined only by the last file processed. If the last operation succeeds, the command returns 0 even if earlier ownership or group changes…
AnalizadaMedia (5.5)0.16%—Uutils Coreutils22/4/202617/6/2026
The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the success or failure of the last file processed. This allows the command to return an exit code of 0 (success) even if errors were encountered…
AnalizadaAlta (7.3)0.20%—Uutils Coreutils22/4/202617/6/2026
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic links to execute…
ModificadaAlta (7.8)0.20%—GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux22/4/20261/9/2026
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the…
ModificadaMedia (5)0.14%—GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux22/4/20261/9/2026
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming…
AnalizadaMedia (5.5)0.15%—GNU BinutilsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux22/4/20261/9/2026
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The…
AnalizadaMedia (4.7)0.12%—Kernel Util-linux3/4/202624/7/2026
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() +…
AnalizadaMedia (5.3)0.62%—Kernel Util-linuxRedhat Hardened Images3/4/202631/8/2026
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable…
ModificadaAlta (8.8)0.66%—Codehaus-plexus Plexus-utils25/3/202616/9/2026
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
ModificadaMedia (6.1)0.17%—GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux23/3/20261/9/2026
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read…
Pendiente de análisisNinguna (0)0.24%—Python PkgutilAI18/3/202617/6/2026
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate…
ModificadaAlta (7.1)0.19%—GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux16/3/20261/9/2026
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure…
ModificadaAlta (7.1)0.19%—GNU BinutilsRedhat Openshift Container PlatformRedhat Enterprise Linux16/3/20261/9/2026
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially…
AnalizadaMedia (4.7)0.27%—GNU Inetutils16/3/202617/6/2026
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
AnalizadaCrítica (9.8)2.4%💥 ExploitGNU Inetutils13/3/202617/6/2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
AnalizadaMedia (6.2)0.18%—GNU Binutils9/3/202617/6/2026
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating…
Orbitaley — Vulnerabilidades