|
1061
|
4.7 |
MEDIUM
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device moves. The extended attribute (xattr) preservation logic uses multiple path-base…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35354
|
2026-04-25 04:04 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1062
|
6.6 |
MEDIUM
Local
|
uutils
|
coreutils
|
The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bit…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2026-35350
|
2026-04-25 04:04 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1063
|
5.7 |
MEDIUM
Adjacent
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft s…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-40045
|
2026-04-25 04:03 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1064
|
7.0 |
HIGH
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local at…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35352
|
2026-04-25 04:03 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1065
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix error handling in slot reset
If the device has not recovered after slot reset is called, it goes to
out label for…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-23358
|
2026-04-25 04:03 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1066
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
drm/amdgpu: Corregir el manejo de errores en el reinicio de ranura
Si el dispositivo no se ha recuperado después de que se llama…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-23358
|
2026-04-25 04:03 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1067
|
4.7 |
MEDIUM
Local
|
uutils
|
coreutils
|
The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before being restrict…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35357
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1068
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix stack-out-of-bounds write in devmap
get_upper_ifindexes() iterates over all upper devices and writes their
indices into …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23359
|
2026-04-25 04:02 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1069
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
bpf: Corrección de escritura fuera de límites de la pila en devmap
get_upper_ifindexes() itera sobre todos los dispositivos supe…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23359
|
2026-04-25 04:02 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1070
|
4.7 |
MEDIUM
Local
|
uutils
|
coreutils
|
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass no-dereference intent. The utility checks if a source path is a symbolic link …
|
CWE-59 CWE-367
Link Following Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-35359
|
2026-04-25 04:02 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|