Retour à la veille
CVE-2026-96276
Score CVSS
9.8
CRITICAL
Description détaillée
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Dernières Vulnérabilités
CVE-2026-91775
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
VOIR DÉTAILS
CVE-2026-88840
BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
VOIR DÉTAILS
CVE-2026-88839
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
VOIR DÉTAILS
