Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

ubuntu логотип

CVE-2026-34078

4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2026-34078

4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 9
EPSS: Низкий
nvd логотип

CVE-2026-34078

4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2026-34078

4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. ...

CVSS3: 10
EPSS: Низкий
fstec логотип

BDU:2026-05831

4 месяца назад

Уязвимость инструмента для управления приложениями и средами Flatpak, связанная с отслеживанием символьных ссылок UNIX, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и выполнить произвольный код

CVSS3: 10
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1713-1

3 месяца назад

Security update for flatpak

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1600-1

3 месяца назад

Security update for flatpak

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1541-1

3 месяца назад

Security update for flatpak

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1511-1

3 месяца назад

Security update for flatpak

EPSS: Низкий
rocky логотип

RLSA-2026:21757

около 2 месяцев назад

Important: flatpak security update

EPSS: Низкий
rocky логотип

RLSA-2026:21756

2 месяца назад

Important: flatpak security update

EPSS: Низкий
rocky логотип

RLSA-2026:21755

около 2 месяцев назад

Important: flatpak security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-21757

17 дней назад

ELSA-2026-21757: flatpak security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-21756

2 месяца назад

ELSA-2026-21756: flatpak security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-21755

около 1 месяца назад

ELSA-2026-21755: flatpak security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-34078

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 10
2%
Низкий
4 месяца назад
redhat логотип
CVE-2026-34078

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 9
2%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34078

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 10
2%
Низкий
4 месяца назад
debian логотип
CVE-2026-34078

Flatpak is a Linux application sandboxing and distribution framework. ...

CVSS3: 10
2%
Низкий
4 месяца назад
fstec логотип
BDU:2026-05831

Уязвимость инструмента для управления приложениями и средами Flatpak, связанная с отслеживанием символьных ссылок UNIX, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и выполнить произвольный код

CVSS3: 10
2%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1713-1

Security update for flatpak

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1600-1

Security update for flatpak

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1541-1

Security update for flatpak

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1511-1

Security update for flatpak

3 месяца назад
rocky логотип
RLSA-2026:21757

Important: flatpak security update

около 2 месяцев назад
rocky логотип
RLSA-2026:21756

Important: flatpak security update

2 месяца назад
rocky логотип
RLSA-2026:21755

Important: flatpak security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-21757

ELSA-2026-21757: flatpak security update (IMPORTANT)

17 дней назад
oracle-oval логотип
ELSA-2026-21756

ELSA-2026-21756: flatpak security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-21755

ELSA-2026-21755: flatpak security update (IMPORTANT)

около 1 месяца назад

Уязвимостей на страницу