CVE Browser
flatpak: Flatpak: Local privilege escalation via symlink traversal in revokefs writer
flatpak: Flatpak: Low integrity or availability impact via symlink manipulation
flatpak: Flatpak: Arbitrary code execution via missing symlink protection
flatpak: xdg-desktop-portal: Flatpak xdg-desktop-portal: File deletion via symlink attack
flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files
Flatpak affected by arbitrary file deletion on the host filesystem
Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
Flatpak may allow access to files outside sandbox for certain apps
Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsing
Flatpak metadata with ANSI control codes can cause misleading terminal output
TIOCLINUX can send commands outside sandbox if running on a virtual console
flatpak-builder can access files outside the build directory.
Permissions granted to applications can be hidden from the user at install time
Sandbox bypass via recent VFS-manipulating syscalls
Sandbox escape via special tokens in .desktop file
Flatpak sandbox escape via spawn portal
flatpak: Sandbox bypass via IOCSTI (incomplete fix for CVE-2017-5226)
flatpak: potential /proc based sandbox escape
flatpak: sandbox escape in D-Bus filtering by a crafted authentication handshake
flatpak: Privilege escalation via setuid/world-writable file permissions
Showing 1 to 21 CVEs · page 1