CVE-2024-4540 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Keycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookie A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an information disclosure vulnerability. Affected products keycloak * keycloak-core rh-sso7-keycloak * rhbk/keycloak-rhel9 * rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * rh-sso-7/sso76-openshift-rhel8 * Matching in nixpkgs pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4 pkgs.terraform-providers.keycloak nixos-unstable ??? nixpkgs-unstable 5.4.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 Package maintainers: 4 @ngerstle Nicholas Gerstle <ngerstle@gmail.com> @NickCao Nick Cao <nickcao@nichi.co> @talyz Kim Lindberger <kim.lindberger@gmail.com> @leona-ya Leona Maroni <nix@leona.is>
pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
CVE-2024-8612 3.8 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Qemu-kvm: information leak in virtio devices A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which has been sent to guest. Once virtqueue_push() finally calls dma_memory_unmap to ummap the in_iov, it may call the address_space_write function to write back the data. Some uninitialized data may exist in the bounce.buffer, leading to an information leak. Affected products qemu * qemu-kvm qemu-kvm-ma virt:av/qemu-kvm virt:rhel/qemu-kvm Matching in nixpkgs pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07 pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 Package maintainers: 11 @oxalica oxalica <oxalicc@pm.me> @DavHau David Hauer <d.hauer.it@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net> @digitalrane Rane <rane+git@junkyard.systems> @CertainLach Yaroslav Bolyukin <iam@lach.pw> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07
pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
CVE-2024-48900 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Moodle: idor when accessing list of badge recipients A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to. Affected products moodle <4.4.4 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-6787 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): NONE created 3 months ago Keycloak: session hijacking via re-authentication A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session. Affected products keycloak <24.0.3 <22.0.10 keycloak-core rh-sso7-keycloak rhbk/keycloak-rhel9 * rhbk/keycloak-rhel9-operator * rhbk/keycloak-operator-bundle * Matching in nixpkgs pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4 pkgs.terraform-providers.keycloak nixos-unstable ??? nixpkgs-unstable 5.4.0 pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0 Package maintainers: 4 @ngerstle Nicholas Gerstle <ngerstle@gmail.com> @NickCao Nick Cao <nickcao@nichi.co> @talyz Kim Lindberger <kim.lindberger@gmail.com> @leona-ya Leona Maroni <nix@leona.is>
pkgs.keycloak Identity and access management for modern applications and services nixos-unstable ??? nixpkgs-unstable 26.3.4
pkgs.python312Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
pkgs.python313Packages.python-keycloak Provides access to the Keycloak API nixos-unstable ??? nixpkgs-unstable 4.0.0
CVE-2024-6505 6.0 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host. Affected products qemu <9.1.0 qemu-kvm qemu-kvm-ma virt:av/qemu-kvm virt:rhel/qemu-kvm Matching in nixpkgs pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07 pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 Package maintainers: 11 @oxalica oxalica <oxalicc@pm.me> @DavHau David Hauer <d.hauer.it@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net> @digitalrane Rane <rane+git@junkyard.systems> @CertainLach Yaroslav Bolyukin <iam@lach.pw> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07
pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
CVE-2024-49394 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago Mutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender. Affected products mutt Matching in nixpkgs pkgs.mutter Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 48.4 pkgs.neomutt Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 20250510 pkgs.mutt-ics Tool to show calendar event details in Mutt nixos-unstable ??? nixpkgs-unstable 0.9.2 pkgs.mutter46 Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 46.8 pkgs.mutt-wizard System for automatically configuring mutt and isync nixos-unstable ??? nixpkgs-unstable 3.3.1 pkgs.notmuch-mutt Mutt support for notmuch nixos-unstable ??? nixpkgs-unstable 0.39 pkgs.font-mutt-misc ClearU pcf fonts nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.pantheon.mutter Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 46.8 pkgs.mutt-with-sidebar Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 2.2.14 pkgs.xorg.fontmuttmisc ClearU pcf fonts nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.vimPlugins.nvim-treesitter-parsers.muttrc nixos-unstable ??? nixpkgs-unstable Package maintainers: 12 @rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org> @mh182 Max Hofer <mh182@chello.at> @SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @jtojnar Jan Tojnar <jtojnar@gmail.com> @davidak David Kleuker <post@davidak.de> @RaitoBezarius Ryan Lahfa <ryan@lahfa.xyz> @erikryb Erik Rybakken <erik.rybakken@math.ntnu.no> @ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com> @peterhoeg Peter Hoeg <peter@hoeg.com>
pkgs.neomutt Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 20250510
pkgs.mutt-wizard System for automatically configuring mutt and isync nixos-unstable ??? nixpkgs-unstable 3.3.1
pkgs.mutt-with-sidebar Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 2.2.14
CVE-2024-49395 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Mutt: neomutt: bcc email header field is indirectly leaked by cryptographic info block In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info. Affected products mutt Matching in nixpkgs pkgs.mutter Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 48.4 pkgs.neomutt Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 20250510 pkgs.mutt-ics Tool to show calendar event details in Mutt nixos-unstable ??? nixpkgs-unstable 0.9.2 pkgs.mutter46 Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 46.8 pkgs.mutt-wizard System for automatically configuring mutt and isync nixos-unstable ??? nixpkgs-unstable 3.3.1 pkgs.notmuch-mutt Mutt support for notmuch nixos-unstable ??? nixpkgs-unstable 0.39 pkgs.font-mutt-misc ClearU pcf fonts nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.pantheon.mutter Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 46.8 pkgs.mutt-with-sidebar Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 2.2.14 pkgs.xorg.fontmuttmisc ClearU pcf fonts nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.vimPlugins.nvim-treesitter-parsers.muttrc nixos-unstable ??? nixpkgs-unstable Package maintainers: 12 @rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org> @mh182 Max Hofer <mh182@chello.at> @SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @jtojnar Jan Tojnar <jtojnar@gmail.com> @davidak David Kleuker <post@davidak.de> @RaitoBezarius Ryan Lahfa <ryan@lahfa.xyz> @erikryb Erik Rybakken <erik.rybakken@math.ntnu.no> @ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com> @peterhoeg Peter Hoeg <peter@hoeg.com>
pkgs.neomutt Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 20250510
pkgs.mutt-wizard System for automatically configuring mutt and isync nixos-unstable ??? nixpkgs-unstable 3.3.1
pkgs.mutt-with-sidebar Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 2.2.14
CVE-2024-49393 7.4 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 3 months ago Mutt: neomutt: to and cc email header fields are not protected by cryptographic signing In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality. Affected products mutt Matching in nixpkgs pkgs.mutter Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 48.4 pkgs.neomutt Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 20250510 pkgs.mutt-ics Tool to show calendar event details in Mutt nixos-unstable ??? nixpkgs-unstable 0.9.2 pkgs.mutter46 Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 46.8 pkgs.mutt-wizard System for automatically configuring mutt and isync nixos-unstable ??? nixpkgs-unstable 3.3.1 pkgs.notmuch-mutt Mutt support for notmuch nixos-unstable ??? nixpkgs-unstable 0.39 pkgs.font-mutt-misc ClearU pcf fonts nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.pantheon.mutter Window manager for GNOME nixos-unstable ??? nixpkgs-unstable 46.8 pkgs.mutt-with-sidebar Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 2.2.14 pkgs.xorg.fontmuttmisc ClearU pcf fonts nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.vimPlugins.nvim-treesitter-parsers.muttrc nixos-unstable ??? nixpkgs-unstable Package maintainers: 12 @rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org> @mh182 Max Hofer <mh182@chello.at> @SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com> @bobby285271 Bobby Rong <rjl931189261@126.com> @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @jtojnar Jan Tojnar <jtojnar@gmail.com> @davidak David Kleuker <post@davidak.de> @RaitoBezarius Ryan Lahfa <ryan@lahfa.xyz> @erikryb Erik Rybakken <erik.rybakken@math.ntnu.no> @ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com> @peterhoeg Peter Hoeg <peter@hoeg.com>
pkgs.neomutt Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 20250510
pkgs.mutt-wizard System for automatically configuring mutt and isync nixos-unstable ??? nixpkgs-unstable 3.3.1
pkgs.mutt-with-sidebar Small but very powerful text-based mail client nixos-unstable ??? nixpkgs-unstable 2.2.14
CVE-2024-8354 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Qemu-kvm: usb: assertion failure in usb_ep_get() A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition. Affected products qemu qemu-kvm qemu-kvm-ma virt:av/qemu-kvm virt:rhel/qemu-kvm Matching in nixpkgs pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07 pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 Package maintainers: 11 @oxalica oxalica <oxalicc@pm.me> @DavHau David Hauer <d.hauer.it@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net> @digitalrane Rane <rane+git@junkyard.systems> @CertainLach Yaroslav Bolyukin <iam@lach.pw> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07
pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
CVE-2024-43427 3.7 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Moodle: admin presets export tool includes some secrets that should not be exported A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party. Affected products moodle <4.4.2 <4.2.9 <4.3.6 <4.1.12 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13