⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2024-58134
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 3 months, 3 weeks ago
Mojolicious versions from 0.999922 through 9.39 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default

Mojolicious versions from 0.999922 through 9.39 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default. These predictable default secrets can be exploited to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.

Mojolicious
=<9.40
=<9.39

pkgs.perl538Packages.Mojolicious

Real-time web framework

pkgs.perl540Packages.Mojolicious

Real-time web framework

pkgs.perl538Packages.MojoliciousPluginI18N

Internationalization Plugin for Mojolicious

pkgs.perl538Packages.MojoliciousPluginMail

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginI18N

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail

Mojolicious Plugin for send mail

pkgs.perl538Packages.MojoliciousPluginStatus

Mojolicious server status

pkgs.perl538Packages.MojoliciousPluginSyslog

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginStatus

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl538Packages.MojoliciousPluginOpenAPI

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl538Packages.MojoliciousPluginWebpack

Mojolicious <3 Webpack

pkgs.perl540Packages.Mojolicious.x86_64-linux

Real-time web framework

pkgs.perl540Packages.MojoliciousPluginOpenAPI

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginWebpack

Mojolicious <3 Webpack

pkgs.perl538Packages.MojoliciousPluginGravatar

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.Mojolicious.aarch64-linux

Real-time web framework

pkgs.perl540Packages.Mojolicious.x86_64-darwin

Real-time web framework

pkgs.perl540Packages.MojoliciousPluginGravatar

Globally Recognized Avatars for Mojolicious

pkgs.perl538Packages.MojoliciousPluginAssetPack

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.Mojolicious.aarch64-darwin

Real-time web framework

pkgs.perl540Packages.MojoliciousPluginAssetPack

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl538Packages.MojoliciousPluginRenderFile

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile

"render_file" helper for Mojolicious

pkgs.perl538Packages.MojoliciousPluginTextExceptions

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTextExceptions

Render exceptions as text in command line user agents

pkgs.perl538Packages.MojoliciousPluginTemplateToolkit

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginI18N.x86_64-linux

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail.x86_64-linux

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginI18N.aarch64-linux

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginI18N.x86_64-darwin

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail.aarch64-linux

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginMail.x86_64-darwin

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginI18N.aarch64-darwin

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail.aarch64-darwin

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginStatus.x86_64-linux

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog.x86_64-linux

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginOpenAPI.x86_64-linux

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginStatus.aarch64-linux

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginStatus.x86_64-darwin

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog.aarch64-linux

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginSyslog.x86_64-darwin

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginWebpack.x86_64-linux

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginGravatar.x86_64-linux

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginOpenAPI.aarch64-linux

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginOpenAPI.x86_64-darwin

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginStatus.aarch64-darwin

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog.aarch64-darwin

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginWebpack.aarch64-linux

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginWebpack.x86_64-darwin

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginAssetPack.x86_64-linux

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginGravatar.aarch64-linux

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginGravatar.x86_64-darwin

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginOpenAPI.aarch64-darwin

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginWebpack.aarch64-darwin

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginAssetPack.aarch64-linux

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginAssetPack.x86_64-darwin

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginGravatar.aarch64-darwin

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile.x86_64-linux

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginAssetPack.aarch64-darwin

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginRenderFile.aarch64-linux

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile.x86_64-darwin

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile.aarch64-darwin

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTextExceptions.x86_64-linux

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.x86_64-linux

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTextExceptions.aarch64-linux

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTextExceptions.x86_64-darwin

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.aarch64-linux

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.x86_64-darwin

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTextExceptions.aarch64-darwin

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.aarch64-darwin

Template Toolkit renderer plugin for Mojolicious
Package maintainers: 4
CVE-2024-58135
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 3 months, 3 weeks ago
Mojolicious versions from 7.28 through 9.39 for Perl may generate weak HMAC session secrets

Mojolicious versions from 7.28 through 9.39 for Perl may generate weak HMAC session secrets. When creating a default app with the "mojo generate app" tool, a weak secret is written to the application's configuration file using the insecure rand() function, and used for authenticating and protecting the integrity of the application's sessions. This may allow an attacker to brute force the application's session keys.

Mojolicious
=<9.40
=<9.39

pkgs.perl538Packages.Mojolicious

Real-time web framework

pkgs.perl540Packages.Mojolicious

Real-time web framework

pkgs.perl538Packages.MojoliciousPluginI18N

Internationalization Plugin for Mojolicious

pkgs.perl538Packages.MojoliciousPluginMail

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginI18N

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail

Mojolicious Plugin for send mail

pkgs.perl538Packages.MojoliciousPluginStatus

Mojolicious server status

pkgs.perl538Packages.MojoliciousPluginSyslog

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginStatus

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl538Packages.MojoliciousPluginOpenAPI

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl538Packages.MojoliciousPluginWebpack

Mojolicious <3 Webpack

pkgs.perl540Packages.Mojolicious.x86_64-linux

Real-time web framework

pkgs.perl540Packages.MojoliciousPluginOpenAPI

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginWebpack

Mojolicious <3 Webpack

pkgs.perl538Packages.MojoliciousPluginGravatar

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.Mojolicious.aarch64-linux

Real-time web framework

pkgs.perl540Packages.Mojolicious.x86_64-darwin

Real-time web framework

pkgs.perl540Packages.MojoliciousPluginGravatar

Globally Recognized Avatars for Mojolicious

pkgs.perl538Packages.MojoliciousPluginAssetPack

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.Mojolicious.aarch64-darwin

Real-time web framework

pkgs.perl540Packages.MojoliciousPluginAssetPack

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl538Packages.MojoliciousPluginRenderFile

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile

"render_file" helper for Mojolicious

pkgs.perl538Packages.MojoliciousPluginTextExceptions

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTextExceptions

Render exceptions as text in command line user agents

pkgs.perl538Packages.MojoliciousPluginTemplateToolkit

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginI18N.x86_64-linux

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail.x86_64-linux

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginI18N.aarch64-linux

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginI18N.x86_64-darwin

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail.aarch64-linux

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginMail.x86_64-darwin

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginI18N.aarch64-darwin

Internationalization Plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginMail.aarch64-darwin

Mojolicious Plugin for send mail

pkgs.perl540Packages.MojoliciousPluginStatus.x86_64-linux

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog.x86_64-linux

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginOpenAPI.x86_64-linux

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginStatus.aarch64-linux

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginStatus.x86_64-darwin

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog.aarch64-linux

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginSyslog.x86_64-darwin

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginWebpack.x86_64-linux

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginGravatar.x86_64-linux

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginOpenAPI.aarch64-linux

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginOpenAPI.x86_64-darwin

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginStatus.aarch64-darwin

Mojolicious server status

pkgs.perl540Packages.MojoliciousPluginSyslog.aarch64-darwin

Plugin for enabling a Mojolicious app to log to syslog

pkgs.perl540Packages.MojoliciousPluginWebpack.aarch64-linux

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginWebpack.x86_64-darwin

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginAssetPack.x86_64-linux

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginGravatar.aarch64-linux

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginGravatar.x86_64-darwin

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginOpenAPI.aarch64-darwin

OpenAPI / Swagger plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginWebpack.aarch64-darwin

Mojolicious <3 Webpack

pkgs.perl540Packages.MojoliciousPluginAssetPack.aarch64-linux

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginAssetPack.x86_64-darwin

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginGravatar.aarch64-darwin

Globally Recognized Avatars for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile.x86_64-linux

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginAssetPack.aarch64-darwin

Compress and convert css, less, sass, javascript and coffeescript files

pkgs.perl540Packages.MojoliciousPluginRenderFile.aarch64-linux

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile.x86_64-darwin

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginRenderFile.aarch64-darwin

"render_file" helper for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTextExceptions.x86_64-linux

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.x86_64-linux

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTextExceptions.aarch64-linux

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTextExceptions.x86_64-darwin

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.aarch64-linux

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.x86_64-darwin

Template Toolkit renderer plugin for Mojolicious

pkgs.perl540Packages.MojoliciousPluginTextExceptions.aarch64-darwin

Render exceptions as text in command line user agents

pkgs.perl540Packages.MojoliciousPluginTemplateToolkit.aarch64-darwin

Template Toolkit renderer plugin for Mojolicious
Package maintainers: 4
CVE-2023-40745
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 4 weeks ago
Libtiff: integer overflow in tiffcp.c

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

libtiff
<4.6.0
*
mingw-libtiff
compact-libtiff
compat-libtiff3

pkgs.libtiff

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-darwin

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-darwin

Library and utilities for working with the TIFF image file format
Package maintainers: 7
CVE-2025-47153
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 3 months, 4 weeks ago
Certain build processes for libuv and Node.js for 32-bit systems, …

Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e.g., building on i386 Debian always uses _FILE_OFFSET_BITS=64 for the libuv dynamic library, but uses the _FILE_OFFSET_BITS global system default of 32 for nodejs), leading to out-of-bounds access. NOTE: this is not a problem in the Node.js software itself. In particular, the Node.js website's download page does not offer prebuilt Node.js for Linux on i386.

nodejs
=<nodejs_20.19.0+dfsg-2_i386.deb

pkgs.nodejs_18

Event-driven I/O framework for the V8 JavaScript engine

pkgs.nodejs_20

Event-driven I/O framework for the V8 JavaScript engine

pkgs.nodejs_22

Event-driven I/O framework for the V8 JavaScript engine

pkgs.corepack_18

Wrappers for npm, pnpm and Yarn via Node.js Corepack

pkgs.corepack_20

Wrappers for npm, pnpm and Yarn via Node.js Corepack

pkgs.corepack_22

Wrappers for npm, pnpm and Yarn via Node.js Corepack

pkgs.nodejs_latest

Event-driven I/O framework for the V8 JavaScript engine

pkgs.nodejs-slim_18

Event-driven I/O framework for the V8 JavaScript engine

pkgs.nodejs-slim_20

Event-driven I/O framework for the V8 JavaScript engine

pkgs.nodejs-slim_22

Event-driven I/O framework for the V8 JavaScript engine

pkgs.corepack_latest

Wrappers for npm, pnpm and Yarn via Node.js Corepack

pkgs.elmPackages.nodejs

Event-driven I/O framework for the V8 JavaScript engine

pkgs.nodejs-slim_latest

Event-driven I/O framework for the V8 JavaScript engine

pkgs.nodejsInstallManuals

  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.haxePackages.hxnodejs_4

Extern definitions for node.js 4.x

pkgs.haxePackages.hxnodejs_6

Extern definitions for node.js 6.9

pkgs.nodejsInstallExecutables

  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.graalvmCEPackages.graalnodejs

High-Performance Polyglot VM (Product: graalnodejs)

pkgs.dockerfile-language-server-nodejs

Language server for Dockerfiles powered by Node.js, TypeScript, and VSCode technologies

pkgs.matrix-sdk-crypto-nodejs-0_1_0-beta_3

No-network-IO implementation of a state machine that handles E2EE for Matrix clients

pkgs.python311Packages.hatch-nodejs-version

Plugins for dealing with NodeJS versions

pkgs.python312Packages.hatch-nodejs-version

Plugins for dealing with NodeJS versions

pkgs.python312Packages.hatch-nodejs-version.x86_64-linux

Plugins for dealing with NodeJS versions

pkgs.python312Packages.hatch-nodejs-version.aarch64-linux

Plugins for dealing with NodeJS versions

pkgs.python312Packages.hatch-nodejs-version.x86_64-darwin

Plugins for dealing with NodeJS versions

pkgs.python312Packages.hatch-nodejs-version.aarch64-darwin

Plugins for dealing with NodeJS versions
Package maintainers: 11
CVE-2023-3576
5.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 4 weeks ago
Libtiff: memory leak in tiffcrop.c

A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service.

libtiff
*
mingw-libtiff
compat-libtiff3

pkgs.libtiff

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-darwin

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-darwin

Library and utilities for working with the TIFF image file format
Package maintainers: 7
CVE-2023-41175
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 4 weeks ago
Libtiff: potential integer overflow in raw2tiff.c

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

libtiff
<4.6.0
*
mingw-libtiff
compact-libtiff
compat-libtiff3

pkgs.libtiff

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-darwin

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-darwin

Library and utilities for working with the TIFF image file format
Package maintainers: 7
CVE-2023-4813
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 4 weeks ago
Glibc: potential use-after-free in gaih_inet()

A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

glibc
*
compat-glibc

pkgs.mtrace

Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3)

pkgs.glibcLocales

Locale information for the GNU C Library

pkgs.glibcLocalesUtf8

Locale information for the GNU C Library

pkgs.locale.x86_64-linux

pkgs.locale.aarch64-linux

pkgs.libiconv.x86_64-linux

pkgs.libiconv.aarch64-linux

Package maintainers: 2
CVE-2023-4806
5.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 3 months, 4 weeks ago
Glibc: potential use-after-free in getaddrinfo()

A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.

glibc
*
compat-glibc

pkgs.mtrace

Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3)

pkgs.glibcLocales

Locale information for the GNU C Library

pkgs.glibcLocalesUtf8

Locale information for the GNU C Library

pkgs.locale.x86_64-linux

pkgs.locale.aarch64-linux

pkgs.libiconv.x86_64-linux

pkgs.libiconv.aarch64-linux

Package maintainers: 2
CVE-2023-40204
9.1 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 4 months ago
WordPress Folders Plugin <= 2.9.2 is vulnerable to Arbitrary File Upload

Unrestricted Upload of File with Dangerous Type vulnerability in Premio Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.This issue affects Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager: from n/a through 2.9.2.

folders
=<2.9.2

pkgs.papirus-folders

Tool to change papirus icon theme color

pkgs.platform-folders

C++ library to look for standard platform directories so that you do not need to write platform-specific code

pkgs.vscode-extensions.moshfeu.compare-folders

Extension allows you to compare folders, show the diffs in a list and present diff in a splitted view side by side

pkgs.vscode-extensions.moshfeu.compare-folders.x86_64-linux

Extension allows you to compare folders, show the diffs in a list and present diff in a splitted view side by side

pkgs.vscode-extensions.moshfeu.compare-folders.aarch64-linux

Extension allows you to compare folders, show the diffs in a list and present diff in a splitted view side by side

pkgs.vscode-extensions.moshfeu.compare-folders.x86_64-darwin

Extension allows you to compare folders, show the diffs in a list and present diff in a splitted view side by side

pkgs.vscode-extensions.moshfeu.compare-folders.aarch64-darwin

Extension allows you to compare folders, show the diffs in a list and present diff in a splitted view side by side
Package maintainers: 3
CVE-2025-4035
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 4 months ago
Libsoup: cookie domain validation bypass via uppercase characters in libsoup

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suffix protections and could allow a malicious website to set cookies for domains it does not own, potentially leading to integrity issues such as session fixation.

libsoup
libsoup3
*

pkgs.libsoup_3

HTTP client/server library for GNOME

pkgs.libsoup_2_4

HTTP client/server library for GNOME

pkgs.libsoup_3.x86_64-linux

HTTP client/server library for GNOME

pkgs.libsoup_3.aarch64-linux

HTTP client/server library for GNOME

pkgs.libsoup_3.x86_64-darwin

HTTP client/server library for GNOME

pkgs.libsoup_2_4.x86_64-linux

HTTP client/server library for GNOME

pkgs.libsoup_3.aarch64-darwin

HTTP client/server library for GNOME

pkgs.libsoup_2_4.aarch64-linux

HTTP client/server library for GNOME

pkgs.libsoup_2_4.x86_64-darwin

HTTP client/server library for GNOME

pkgs.libsoup_2_4.aarch64-darwin

HTTP client/server library for GNOME

pkgs.tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4"

Test whether libsoup-2.74.3 exposes pkg-config modules libsoup-gnome-2.4
Package maintainers: 6