Known vulnerabilities in coreutils
Vendor:
GNU
Software:
coreutils
Software CPE:
cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*
Website:
https://www.gnu.org/
Total vulnerabilities:
4
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.1
Breakdown by Severity Chart
9.11
9.10
9.9
9.8
9.7
9.6
9.5
9.4
9.3
9.2
9.1
9.0
8.32
8.31
8.30
8.29
8.28
8.27
8.26
8.25
8.24
8.23
8.22
8.21
8.20
8.19
8.18
8.17
8.16
8.15
8.14
8.13
8.12
8.11
8.10
8.9
8.8
8.7
8.6
8.5
8.3
8.2
8.0
7.0
6.9.92
6.9.91
6.9.90
6.9.89
6.1
6.0
5.90
5.3.0
5.2.0
5.1.3
5.1.2
5.1.1
5.1.0
5.0.91
5.0.90
5.0.1
5.0
4.5.12
4.5.11
4.5.10
4.5.9
4.5.8
4.5.7
4.5.6
4.5.5
4.5.4
4.5.3
4.5.2
4.5.1
8.4
6.10
5.91
5.97
5.94
6.9
5.96
5.93
5.95
5.92
7.6
6.7
7.3
6.4
6.12
7.5
6.6
8.1
7.2
6.3
7.4
6.5
7.1
6.2
6.8
6.11
5.2.1
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU109921 - Out-of-bounds read CVE-2025-5278 |
CWE-125 | Medium | - | 29.05.2025 |
SB2025052969 SB2025052971 SB2025052972 and 4 more |
||
| #VU85620 - Heap-based Buffer Overflow CVE-2024-0684 |
CWE-122 | Low | - | 19.01.2024 |
SB2024011930 SB2024011932 SB2024032902 and 2 more |
||
| #VU33153 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2017-18018 |
CWE-362 | Low | - | 04.01.2018 |
SB2018010433 SB2018081632 SB2022091932 and 3 more |
||
| #VU38228 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2015-1865 |
CWE-362 | Low | - | 20.09.2017 |
SB2017092018 |