Записи flatpak
18 опубликованных записей вендора flatpak.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-61 UNIX Symbolic Link (Symlink) Following2
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-42472Эксплойта нет | Flatpak may allow access to files outside sandbox for certain appsflatpak · flatpak · CWE-74 | Критическая10,0 | — | 1,3 % | 15 авг. 2024 г. |
37Наблюдать | CVE-2019-10063Эксплойта нет | Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass.flatpak · flatpak · CWE-20 | Критическая9,0 | — | 1,9 % | 26 мар. 2019 г. |
37Наблюдать | CVE-2026-34078Эксплойта нет | Flatpak has a complete sandbox escape leading to host file access and code execution in the host contextflatpak · flatpak · CWE-61 | Критическая9,3 | — | 0,9 % | 7 апр. 2026 г. |
35Наблюдать | CVE-2021-21261Эксплойта нет | Flatpak sandbox escape via spawn portalflatpak · flatpak · CWE-74 | Высокая8,8 | — | 0,6 % | 14 янв. 2021 г. |
35Наблюдать | CVE-2018-6560Эксплойта нет | In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used toflatpak · flatpak · CWE-436 | Высокая8,8 | — | 0,4 % | 2 февр. 2018 г. |
34Наблюдать | CVE-2021-43860Эксплойта нет | Permissions granted to applications can be hidden from the user at install timeflatpak · flatpak · CWE-269 | Высокая8,6 | — | 1,3 % | 12 янв. 2022 г. |
34Наблюдать | CVE-2026-34079Эксплойта нет | Flatpak affected by arbitrary file deletion on the host filesystemflatpak · flatpak · CWE-22 | Высокая8,7 | — | 0,4 % | 7 апр. 2026 г. |
33Наблюдать | CVE-2024-32462Proof of concept | Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsingflatpak · flatpak · CWE-88 | Высокая8,4 | — | 0,5 % | 18 апр. 2024 г. |
32Наблюдать | CVE-2021-21381Эксплойта нет | Sandbox escape via special tokens in .desktop fileflatpak · flatpak · CWE-74 | Высокая8,2 | — | 1,5 % | 11 мар. 2021 г. |
32Наблюдать | CVE-2019-8308Эксплойта нет | Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a flatpak · flatpak · CWE-668 | Высокая8,2 | — | 0,5 % | 12 февр. 2019 г. |
31Наблюдать | CVE-2021-41133Эксплойта нет | Sandbox bypass via recent VFS-manipulating syscallsflatpak · flatpak · CWE-20 | Высокая7,8 | — | 0,4 % | 8 окт. 2021 г. |
31Наблюдать | CVE-2017-9780Эксплойта нет | In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for exflatpak · flatpak · CWE-732 | Высокая7,8 | — | 0,4 % | 21 июн. 2017 г. |
28Наблюдать | CVE-2026-39977Эксплойта нет | flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence filesflatpak · flatpak-builder · CWE-22 | Высокая7,1 | — | 0,4 % | 9 апр. 2026 г. |
27Наблюдать | CVE-2022-21682Эксплойта нет | flatpak-builder can access files outside the build directory.flatpak · flatpak · CWE-22 | Средняя6,5 | — | 1,7 % | 13 янв. 2022 г. |
27Наблюдать | CVE-2026-34080Эксплойта нет | xdg-dbus-proxy has an eavesdrop filter bypass allowing message interceptionflatpak · xdg-dbus-proxy · CWE-1289 | Средняя6,8 | — | 0,2 % | 7 апр. 2026 г. |
26Наблюдать | CVE-2023-28100Эксплойта нет | TIOCLINUX can send commands outside sandbox if running on a virtual consoleflatpak · flatpak · CWE-20 | Средняя6,5 | — | 0,9 % | 16 мар. 2023 г. |
25Наблюдать | CVE-2026-40354Эксплойта нет | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlinkflatpak · xdg-desktop-portal · CWE-61 | Средняя6,3 | — | 0,2 % | 10 апр. 2026 г. |
17Наблюдать | CVE-2023-28101Эксплойта нет | Flatpak metadata with ANSI control codes can cause misleading terminal outputflatpak · flatpak · CWE-116 | Средняя4,3 | — | 0,9 % | 16 мар. 2023 г. |
- CVE-2024-4247240В плане
Flatpak may allow access to files outside sandbox for certain apps
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %flatpak · flatpak15 авг. 2024 г.
- CVE-2019-1006337Наблюдать
Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %flatpak · flatpak26 мар. 2019 г.
- CVE-2026-3407837Наблюдать
Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %flatpak · flatpak7 апр. 2026 г.
- CVE-2021-2126135Наблюдать
Flatpak sandbox escape via spawn portal
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %flatpak · flatpak14 янв. 2021 г.
- CVE-2018-656035Наблюдать
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %flatpak · flatpak2 февр. 2018 г.
- CVE-2021-4386034Наблюдать
Permissions granted to applications can be hidden from the user at install time
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %flatpak · flatpak12 янв. 2022 г.
- CVE-2026-3407934Наблюдать
Flatpak affected by arbitrary file deletion on the host filesystem
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %flatpak · flatpak7 апр. 2026 г.
- CVE-2024-3246233Наблюдать
Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsing
ВысокаяCVSS 8,4Proof of conceptEPSS 1 %flatpak · flatpak18 апр. 2024 г.
- CVE-2021-2138132Наблюдать
Sandbox escape via special tokens in .desktop file
ВысокаяCVSS 8,2Эксплойта нетEPSS 2 %flatpak · flatpak11 мар. 2021 г.
- CVE-2019-830832Наблюдать
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %flatpak · flatpak12 февр. 2019 г.
- CVE-2021-4113331Наблюдать
Sandbox bypass via recent VFS-manipulating syscalls
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %flatpak · flatpak8 окт. 2021 г.
- CVE-2017-978031Наблюдать
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for ex
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %flatpak · flatpak21 июн. 2017 г.
- CVE-2026-3997728Наблюдать
flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %flatpak · flatpak-builder9 апр. 2026 г.
- CVE-2022-2168227Наблюдать
flatpak-builder can access files outside the build directory.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %flatpak · flatpak13 янв. 2022 г.
- CVE-2026-3408027Наблюдать
xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
СредняяCVSS 6,8Эксплойта нетEPSS 0 %flatpak · xdg-dbus-proxy7 апр. 2026 г.
- CVE-2023-2810026Наблюдать
TIOCLINUX can send commands outside sandbox if running on a virtual console
СредняяCVSS 6,5Эксплойта нетEPSS 1 %flatpak · flatpak16 мар. 2023 г.
- CVE-2026-4035425Наблюдать
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink
СредняяCVSS 6,3Эксплойта нетEPSS 0 %flatpak · xdg-desktop-portal10 апр. 2026 г.
- CVE-2023-2810117Наблюдать
Flatpak metadata with ANSI control codes can cause misleading terminal output
СредняяCVSS 4,3Эксплойта нетEPSS 1 %flatpak · flatpak16 мар. 2023 г.