Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

github логотип

GHSA-9h57-x6hw-v4j8

около 2 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2026-2604

около 2 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2026-2604

6 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-2604

около 2 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2026-2604

около 2 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison log ...

CVSS3: 5.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20864-1

2 месяца назад

Security update for evolution-data-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0776-1

5 месяцев назад

Security update for evolution-data-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0775-1

5 месяцев назад

Security update for evolution-data-server

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9h57-x6hw-v4j8

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-2604

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-2604

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-2604

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-2604

A flaw was found in evolution-data-server. Inconsistent comparison log ...

CVSS3: 5.6
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20864-1

Security update for evolution-data-server

0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0776-1

Security update for evolution-data-server

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0775-1

Security update for evolution-data-server

0%
Низкий
5 месяцев назад

Уязвимостей на страницу