Known vulnerabilities in flatpak (Debian package) 1.2.5-0+deb10u1~bpo9+1

Vendor: Debian
Version: 1.2.5-0+deb10u1~bpo9+1
Software CPE: cpe:2.3:o:debian:flatpak_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting flatpak (Debian package) version 1.2.5-0+deb10u1~bpo9+1 flatpak (Debian package) 1.2.5-0+deb10u1~bpo9+1 is affected by 5 vulnerabilities: 3 medium, 2 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU59689 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-21682
CWE-22 Medium
No
No
1.10.7-0+deb11u1 18.01.2022 SB2022011811
SB2022012525
SB2022110837
and 8 more
#VU59654 - Permissions, Privileges, and Access Controls
CVE-2021-43860
CWE-264 Medium
No
No
1.10.7-0+deb11u1 17.01.2022 SB2022011715
SB2022012525
SB2022051141
and 8 more
#VU57176 - Permissions, Privileges, and Access Controls
CVE-2021-41133
CWE-264 Low
No
No
1.10.5-0+deb11u1 08.10.2021 SB2021100815
SB2021101417
SB2021110212
and 17 more
#VU51443 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-21381
CWE-74 Medium
No
No
1.2.5-0+deb10u4 14.03.2021 SB2021031112
SB2021031403
SB2021031408
and 11 more
#VU49587 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-21261
CWE-94 Low
No
No
1.2.5-0+deb10u2 14.01.2021 SB2021011821
SB2021011822
SB2021012105
and 12 more