CVE Browser

More filters (active)
CVE-2026-96808 HIGH

flatpak: Flatpak: Local privilege escalation via symlink traversal in revokefs writer

CVSS 7.8 EPSS 0.12% Sep 23, 2026
CVE-2026-96807 MEDIUM

flatpak: Flatpak: Low integrity or availability impact via symlink manipulation

CVSS 4.5 EPSS 0.12% Sep 23, 2026
CVE-2026-90616 HIGH

flatpak: Flatpak: Arbitrary code execution via missing symlink protection

CVSS 7.8 EPSS 0.18% Sep 12, 2026
CVE-2026-40354 MEDIUM

flatpak: xdg-desktop-portal: Flatpak xdg-desktop-portal: File deletion via symlink attack

CVSS 6.3 EPSS 0.16% Apr 11, 2026
CVE-2026-39977 HIGH

flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files

CVSS 7.1 EPSS 0.38% Apr 9, 2026
CVE-2026-34079 HIGH

Flatpak affected by arbitrary file deletion on the host filesystem

CVSS 8.7 EPSS 0.44% Apr 7, 2026
CVE-2026-34078 CRITICAL

Flatpak has a complete sandbox escape leading to host file access and code execution in the host context

CVSS 9.3 EPSS 0.90% Apr 7, 2026
CVE-2026-34080 MEDIUM

xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception

CVSS 6.8 EPSS 0.16% Apr 7, 2026
CVE-2024-42472 CRITICAL

Flatpak may allow access to files outside sandbox for certain apps

CVSS 10.0 EPSS 1.27% Aug 15, 2024
CVE-2024-32462 HIGH

Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsing

CVSS 8.4 EPSS 0.51% Apr 18, 2024
CVE-2023-28101 MEDIUM

Flatpak metadata with ANSI control codes can cause misleading terminal output

CVSS 6.2 EPSS 0.88% Mar 16, 2023
CVE-2023-28100 CRITICAL

TIOCLINUX can send commands outside sandbox if running on a virtual console

CVSS 10.0 EPSS 0.87% Mar 16, 2023
CVE-2022-21682 HIGH

flatpak-builder can access files outside the build directory.

CVSS 7.7 EPSS 1.68% Jan 13, 2022
CVE-2021-43860 HIGH

Permissions granted to applications can be hidden from the user at install time

CVSS 8.6 EPSS 1.34% Jan 12, 2022
CVE-2021-41133 HIGH

Sandbox bypass via recent VFS-manipulating syscalls

CVSS 8.8 EPSS 0.44% Oct 8, 2021
CVE-2021-21381 HIGH

Sandbox escape via special tokens in .desktop file

CVSS 8.2 EPSS 1.55% Mar 11, 2021
CVE-2021-21261 HIGH

Flatpak sandbox escape via spawn portal

CVSS 8.8 EPSS 0.57% Jan 14, 2021
CVE-2019-10063 CRITICAL

flatpak: Sandbox bypass via IOCSTI (incomplete fix for CVE-2017-5226)

CVSS 9.0 EPSS 1.91% Mar 26, 2019
CVE-2019-8308 HIGH

flatpak: potential /proc based sandbox escape

CVSS 8.2 EPSS 0.47% Feb 12, 2019
CVE-2018-6560 HIGH

flatpak: sandbox escape in D-Bus filtering by a crafted authentication handshake

CVSS 8.8 EPSS 0.41% Feb 2, 2018
CVE-2017-9780 HIGH

flatpak: Privilege escalation via setuid/world-writable file permissions

CVSS 7.8 EPSS 0.36% Jun 21, 2017

Showing 1 to 21 CVEs · page 1