flatpak kayıtları
flatpak üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-61 UNIX Symbolic Link (Symlink) Following2
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-42472İstismar yok | Flatpak may allow access to files outside sandbox for certain appsflatpak · flatpak · CWE-74 | Kritik10,0 | — | %1,3 | 15 Ağu 2024 |
37İzleyin | CVE-2019-10063İstismar yok | Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass.flatpak · flatpak · CWE-20 | Kritik9,0 | — | %1,9 | 26 Mar 2019 |
37İzleyin | CVE-2026-34078İstismar yok | Flatpak has a complete sandbox escape leading to host file access and code execution in the host contextflatpak · flatpak · CWE-61 | Kritik9,3 | — | %0,9 | 7 Nis 2026 |
35İzleyin | CVE-2021-21261İstismar yok | Flatpak sandbox escape via spawn portalflatpak · flatpak · CWE-74 | Yüksek8,8 | — | %0,6 | 14 Oca 2021 |
35İzleyin | CVE-2018-6560İstismar yok | In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used toflatpak · flatpak · CWE-436 | Yüksek8,8 | — | %0,4 | 2 Şub 2018 |
34İzleyin | CVE-2021-43860İstismar yok | Permissions granted to applications can be hidden from the user at install timeflatpak · flatpak · CWE-269 | Yüksek8,6 | — | %1,3 | 12 Oca 2022 |
34İzleyin | CVE-2026-34079İstismar yok | Flatpak affected by arbitrary file deletion on the host filesystemflatpak · flatpak · CWE-22 | Yüksek8,7 | — | %0,4 | 7 Nis 2026 |
33İzleyin | CVE-2024-32462Kavram kanıtı | Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsingflatpak · flatpak · CWE-88 | Yüksek8,4 | — | %0,5 | 18 Nis 2024 |
32İzleyin | CVE-2021-21381İstismar yok | Sandbox escape via special tokens in .desktop fileflatpak · flatpak · CWE-74 | Yüksek8,2 | — | %1,5 | 11 Mar 2021 |
32İzleyin | CVE-2019-8308İstismar yok | Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a flatpak · flatpak · CWE-668 | Yüksek8,2 | — | %0,5 | 12 Şub 2019 |
31İzleyin | CVE-2021-41133İstismar yok | Sandbox bypass via recent VFS-manipulating syscallsflatpak · flatpak · CWE-20 | Yüksek7,8 | — | %0,4 | 8 Eki 2021 |
31İzleyin | CVE-2017-9780İstismar yok | In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for exflatpak · flatpak · CWE-732 | Yüksek7,8 | — | %0,4 | 21 Haz 2017 |
28İzleyin | CVE-2026-39977İstismar yok | flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence filesflatpak · flatpak-builder · CWE-22 | Yüksek7,1 | — | %0,4 | 9 Nis 2026 |
27İzleyin | CVE-2022-21682İstismar yok | flatpak-builder can access files outside the build directory.flatpak · flatpak · CWE-22 | Orta6,5 | — | %1,7 | 13 Oca 2022 |
27İzleyin | CVE-2026-34080İstismar yok | xdg-dbus-proxy has an eavesdrop filter bypass allowing message interceptionflatpak · xdg-dbus-proxy · CWE-1289 | Orta6,8 | — | %0,2 | 7 Nis 2026 |
26İzleyin | CVE-2023-28100İstismar yok | TIOCLINUX can send commands outside sandbox if running on a virtual consoleflatpak · flatpak · CWE-20 | Orta6,5 | — | %0,9 | 16 Mar 2023 |
25İzleyin | CVE-2026-40354İstismar yok | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlinkflatpak · xdg-desktop-portal · CWE-61 | Orta6,3 | — | %0,2 | 10 Nis 2026 |
17İzleyin | CVE-2023-28101İstismar yok | Flatpak metadata with ANSI control codes can cause misleading terminal outputflatpak · flatpak · CWE-116 | Orta4,3 | — | %0,9 | 16 Mar 2023 |
- CVE-2024-4247240Planlayın
Flatpak may allow access to files outside sandbox for certain apps
KritikCVSS 10,0İstismar yokEPSS %1flatpak · flatpak15 Ağu 2024
- CVE-2019-1006337İzleyin
Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass.
KritikCVSS 9,0İstismar yokEPSS %2flatpak · flatpak26 Mar 2019
- CVE-2026-3407837İzleyin
Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
KritikCVSS 9,3İstismar yokEPSS %1flatpak · flatpak7 Nis 2026
- CVE-2021-2126135İzleyin
Flatpak sandbox escape via spawn portal
YüksekCVSS 8,8İstismar yokEPSS %1flatpak · flatpak14 Oca 2021
- CVE-2018-656035İzleyin
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to
YüksekCVSS 8,8İstismar yokEPSS %0flatpak · flatpak2 Şub 2018
- CVE-2021-4386034İzleyin
Permissions granted to applications can be hidden from the user at install time
YüksekCVSS 8,6İstismar yokEPSS %1flatpak · flatpak12 Oca 2022
- CVE-2026-3407934İzleyin
Flatpak affected by arbitrary file deletion on the host filesystem
YüksekCVSS 8,7İstismar yokEPSS %0flatpak · flatpak7 Nis 2026
- CVE-2024-3246233İzleyin
Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsing
YüksekCVSS 8,4Kavram kanıtıEPSS %1flatpak · flatpak18 Nis 2024
- CVE-2021-2138132İzleyin
Sandbox escape via special tokens in .desktop file
YüksekCVSS 8,2İstismar yokEPSS %2flatpak · flatpak11 Mar 2021
- CVE-2019-830832İzleyin
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a
YüksekCVSS 8,2İstismar yokEPSS %0flatpak · flatpak12 Şub 2019
- CVE-2021-4113331İzleyin
Sandbox bypass via recent VFS-manipulating syscalls
YüksekCVSS 7,8İstismar yokEPSS %0flatpak · flatpak8 Eki 2021
- CVE-2017-978031İzleyin
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for ex
YüksekCVSS 7,8İstismar yokEPSS %0flatpak · flatpak21 Haz 2017
- CVE-2026-3997728İzleyin
flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files
YüksekCVSS 7,1İstismar yokEPSS %0flatpak · flatpak-builder9 Nis 2026
- CVE-2022-2168227İzleyin
flatpak-builder can access files outside the build directory.
OrtaCVSS 6,5İstismar yokEPSS %2flatpak · flatpak13 Oca 2022
- CVE-2026-3408027İzleyin
xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
OrtaCVSS 6,8İstismar yokEPSS %0flatpak · xdg-dbus-proxy7 Nis 2026
- CVE-2023-2810026İzleyin
TIOCLINUX can send commands outside sandbox if running on a virtual console
OrtaCVSS 6,5İstismar yokEPSS %1flatpak · flatpak16 Mar 2023
- CVE-2026-4035425İzleyin
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink
OrtaCVSS 6,3İstismar yokEPSS %0flatpak · xdg-desktop-portal10 Nis 2026
- CVE-2023-2810117İzleyin
Flatpak metadata with ANSI control codes can cause misleading terminal output
OrtaCVSS 4,3İstismar yokEPSS %1flatpak · flatpak16 Mar 2023