Vendorsuutilscoreutilsall versions
Vulnerabilities

uutils coreutils

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

44CVEs
CVE-2026-35368
uutils coreutils chroot Local Privilege Escalation and chroot Escape in via Name Service Switch (NSS) Injection
Published 2026-04-22 · Analyzed
7.8EPSS 0.001
CVE-2026-35349
uutils coreutils Path-Based Safety Bypass with --preserve-root
Published 2026-04-22 · Analyzed
7.7EPSS 0.002
CVE-2026-35338
uutils coreutils chmod Path Traversal Bypass of --preserve-root
Published 2026-04-22 · Analyzed
7.3EPSS 0.002
CVE-2026-35341
uutils coreutils mkfifo Unauthorized Permission Change on Existing Files
Published 2026-04-22 · Analyzed
7.1EPSS 0.002
CVE-2026-35352
uutils coreutils mkfifo Privilege Escalation via TOCTOU Race Condition
Published 2026-04-22 · Modified
7.0EPSS 0.001
CVE-2026-35365
uutils coreutils mv Denial of Service and Data Duplication via Improper Symlink Expansion
Published 2026-04-22 · Analyzed
6.6EPSS 0.002
CVE-2026-35350
uutils coreutils cp Unexpected Privileged Executable Creation with -p
Published 2026-04-22 · Analyzed
6.6EPSS 0.001
CVE-2026-35355
uutils coreutils install Arbitrary File Overwrite via Symlink TOCTOU Race
Published 2026-04-22 · Analyzed
6.3EPSS 0.001
CVE-2026-35356
uutils coreutils install Arbitrary File Overwrite with -D via Path Component Symlink Race
Published 2026-04-22 · Analyzed
6.3EPSS 0.001
CVE-2026-35360
uutils coreutils touch Arbitrary File Truncation via TOCTOU Race Condition
Published 2026-04-22 · Analyzed
6.3EPSS 0.001
CVE-2026-35364
uutils coreutils mv Arbitrary File Overwrite via Cross-Device TOCTOU Race Condition
Published 2026-04-22 · Analyzed
6.3EPSS 0.001
CVE-2026-35374
uutils coreutils split Arbitrary File Truncation via Time-of-Check to Time-of-Use (TOCTOU) Race Condition
Published 2026-04-22 · Analyzed
6.3EPSS 0.001
CVE-2026-35376
uutils coreutils chcon Security Bypass and Mandatory Access Control (MAC) Inconsistency via TOCTOU Race Condition
Published 2026-04-22 · Analyzed
5.8EPSS 0.001
CVE-2026-35363
uutils coreutils rm Safeguard Bypass via Improper Path Normalization
Published 2026-04-22 · Analyzed
5.6EPSS 0.002
CVE-2026-35358
uutils coreutils cp Semantic Loss and Potential Denial of Service with -R via Device Node Stream Reading
Published 2026-04-22 · Analyzed
5.5EPSS 0.002
CVE-2026-35380
uutils coreutils cut Local Logic Error and Data Integrity Issue in Delimiter Parsing
Published 2026-04-22 · Analyzed
5.5EPSS 0.002
CVE-2026-35339
uutils coreutils chmod False Success Exit Code in Recursive Mode
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-35340
uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-35348
uutils coreutils sort Local Denial of Service via Forced UTF-8 Parsing
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-35369
uutils coreutils kill System-wide Process Termination and Denial of Service via Argument Misinterpretation
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-35373
uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-35345
uutils coreutils tail Privileged Information Disclosure via Symlink Replacement Race
Published 2026-04-22 · Analyzed
5.3EPSS 0.001
CVE-2026-35372
uutils coreutils ln Security Bypass via Improper Handling of the --no-dereference Flag
Published 2026-04-22 · Analyzed
5.0EPSS 0.001
CVE-2026-35359
uutils coreutils cp Information Disclosure via Time-of-Check to Time-of-Use Symlink Swap
Published 2026-04-22 · Analyzed
4.7EPSS 0.001
CVE-2026-35354
uutils coreutils mv Security Xattr TOCTOU Race in Cross-Device
Published 2026-04-22 · Analyzed
4.7EPSS 0.001
CVE-2026-35357
uutils coreutils cp Information Disclosure via Permission Handling Race
Published 2026-04-22 · Analyzed
4.7EPSS 0.001
CVE-2026-35366
uutils coreutils printenv Security Inspection Bypass via UTF-8 Enforcement
Published 2026-04-22 · Analyzed
4.4EPSS 0.002
CVE-2026-35361
uutils coreutils mknod Security Label Inconsistency and Broken Cleanup on SELinux Systems
Published 2026-04-22 · Analyzed
4.4EPSS 0.001
CVE-2026-35347
uutils coreutils comm Silent Data Loss or Denial of Service via Improper Input Validation
Published 2026-04-22 · Analyzed
4.4EPSS 0.001
CVE-2026-35370
uutils coreutils id Incorrect Access-Control Decisions via Misrepresented Group Membership
Published 2026-04-22 · Analyzed
4.4EPSS 0.001
CVE-2026-35351
uutils coreutils mv Silent Ownership Loss in Cross-Device Operations
Published 2026-04-22 · Analyzed
4.2EPSS 0.001
CVE-2026-35362
uutils coreutils Missing TOCTOU Protection on Non-Linux Unix Platforms in Safe Traversal Module
Published 2026-04-22 · Analyzed
3.6EPSS 0.002
CVE-2026-35381
uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
Published 2026-04-22 · Analyzed
3.3EPSS 0.002
CVE-2026-35346
uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization
Published 2026-04-22 · Analyzed
3.3EPSS 0.002
CVE-2026-35378
uutils coreutils expr Local Denial of Service via Eager Evaluation of Parenthesized Subexpressions
Published 2026-04-22 · Analyzed
3.3EPSS 0.002
CVE-2026-35379
uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling
Published 2026-04-22 · Analyzed
3.3EPSS 0.001
CVE-2026-35375
uutils coreutils split Local Data Integrity Issue via Lossy Filename Encoding
Published 2026-04-22 · Analyzed
3.3EPSS 0.001
CVE-2026-35343
uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters
Published 2026-04-22 · Analyzed
3.3EPSS 0.001
CVE-2026-35342
uutils coreutils mktemp Insecure Temporary File Placement via Empty TMPDIR
Published 2026-04-22 · Analyzed
3.3EPSS 0.001
CVE-2026-35371
uutils coreutils id Misleading Identity Reporting in Pretty Print Mode
Published 2026-04-22 · Analyzed
3.3EPSS 0.001
1 / 2Next →