Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2024-45620 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: incorrect handling of the length of buffers or files in pkcs15init A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2024-45617 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2024-45619 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: incorrect handling length of buffers or files in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2024-45618 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2024-45616 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: uninitialized values after incorrect check or usage of apdu response values in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2024-45615 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: pkcs15init: usage of uninitialized values in libopensc and pkcs15init A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net> CVE-2024-5148 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition. gnome-remote-desktop <46.2 pkgs.gnome-remote-desktop GNOME Remote Desktop server nixos-unstable ??? nixpkgs-unstable 48.1 Package maintainers: 4 @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com> CVE-2024-8235 6.2 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago Libvirt: crash of virtinterfaced via virconnectlistinterfaces() A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon. libvirt <10.7.0 * virt:av/libvirt virt:rhel/libvirt pkgs.libvirt Toolkit to interact with the virtualization capabilities of recent versions of Linux and other OSes nixos-unstable ??? nixpkgs-unstable 11.6.0 pkgs.libvirt-glib Wrapper library of libvirt for glib-based applications nixos-unstable ??? nixpkgs-unstable 5.0.0 pkgs.python312Packages.libvirt Libvirt Python bindings nixos-unstable ??? nixpkgs-unstable 11.6.0 pkgs.python313Packages.libvirt Libvirt Python bindings nixos-unstable ??? nixpkgs-unstable 11.6.0 pkgs.rubyPackages.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.prometheus-libvirt-exporter Prometheus metrics exporter for libvirt nixos-unstable ??? nixpkgs-unstable 2.3.3 pkgs.terraform-providers.libvirt nixos-unstable ??? nixpkgs-unstable 0.8.3 pkgs.rubyPackages_3_1.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.rubyPackages_3_2.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.rubyPackages_3_3.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.rubyPackages_3_4.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 Package maintainers: 4 @farcaller Vladimir Pouzanov <farcaller@gmail.com> @globin Robin Gloster <mail@glob.in> @fpletz Franz Pletz <fpletz@fnordicwalking.de> @lovesegfault Bernardo Meurer <meurerbernardo@gmail.com> CVE-2024-1545 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Fault Injection of RSA encryption in WolfCrypt Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure. wolfssl =<5.6.6 pkgs.wolfssl Small, fast, portable implementation of TLS/SSL for embedded devices nixos-unstable ??? nixpkgs-unstable 5.8.2 Package maintainers: 2 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @vifino Adrian Pistol <vifino@tty.sh> CVE-2024-43951 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Tempera theme <= 1.8.2 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Tempera allows Stored XSS.This issue affects Tempera: from n/a through 1.8.2. tempera =<1.8.2 pkgs.home-assistant-component-tests.eddystone_temperature Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 3 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @dotlambda Robert Schütz <rschuetz17@gmail.com>
CVE-2024-45620 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: incorrect handling of the length of buffers or files in pkcs15init A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45617 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45619 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: incorrect handling length of buffers or files in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45618 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45616 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: uninitialized values after incorrect check or usage of apdu response values in libopensc A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @michaeladler Michael Adler <therisen06@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @Curious-r Curious <curious@curious.host> @pca006132 pca006132 <john.lck40@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-45615 3.9 LOW CVSS version: 3.1 Attack vector (AV): PHYSICAL Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Libopensc: pkcs15init: usage of uninitialized values in libopensc and pkcs15init A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed. opensc libopensc <0.26.0 pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1 pkgs.openscad 3D parametric model compiler nixos-unstable ??? nixpkgs-unstable 2021.01 pkgs.openscap NIST Certified SCAP 1.2 toolkit nixos-unstable ??? nixpkgs-unstable 1.4.2 pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1 pkgs.openscenegraph 3D graphics toolkit nixos-unstable ??? nixpkgs-unstable 3.6.5 pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04 pkgs.kakounePlugins.openscad-kak nixos-unstable ??? nixpkgs-unstable 2020-12-10 pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2 Package maintainers: 8 @Curious-r Curious <curious@curious.host> @c-h-johnson Charles Johnson <charles@charlesjohnson.name> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @pca006132 pca006132 <john.lck40@gmail.com> @michaeladler Michael Adler <therisen06@gmail.com> @bjornfor Bjørn Forsman <bjorn.forsman@gmail.com> @Tochiaha Tochukwu Ahanonu <tochiahan@proton.me> @aanderse Aaron Andersen <aaron@fosslib.net>
pkgs.opensc Set of libraries and utilities to access smart cards nixos-unstable ??? nixpkgs-unstable 0.26.1
pkgs.openscad-lsp LSP (Language Server Protocol) server for OpenSCAD nixos-unstable ??? nixpkgs-unstable 2.0.1
pkgs.openscad-unstable 3D parametric model compiler (unstable) nixos-unstable ??? nixpkgs-unstable 2025-06-04
pkgs.vscode-extensions.antyos.openscad OpenSCAD highlighting, snippets, and more for VSCode nixos-unstable ??? nixpkgs-unstable 1.3.2
CVE-2024-5148 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 1 month, 1 week ago Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition. gnome-remote-desktop <46.2 pkgs.gnome-remote-desktop GNOME Remote Desktop server nixos-unstable ??? nixpkgs-unstable 48.1 Package maintainers: 4 @hedning Tor Hedin Brønner <torhedinbronner@gmail.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @dasj19 Daniel Șerbănescu <daniel@serbanescu.dk> @bobby285271 Bobby Rong <rjl931189261@126.com>
CVE-2024-8235 6.2 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 1 month, 1 week ago Libvirt: crash of virtinterfaced via virconnectlistinterfaces() A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read-only socket to crash the virtinterfaced daemon. libvirt <10.7.0 * virt:av/libvirt virt:rhel/libvirt pkgs.libvirt Toolkit to interact with the virtualization capabilities of recent versions of Linux and other OSes nixos-unstable ??? nixpkgs-unstable 11.6.0 pkgs.libvirt-glib Wrapper library of libvirt for glib-based applications nixos-unstable ??? nixpkgs-unstable 5.0.0 pkgs.python312Packages.libvirt Libvirt Python bindings nixos-unstable ??? nixpkgs-unstable 11.6.0 pkgs.python313Packages.libvirt Libvirt Python bindings nixos-unstable ??? nixpkgs-unstable 11.6.0 pkgs.rubyPackages.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.prometheus-libvirt-exporter Prometheus metrics exporter for libvirt nixos-unstable ??? nixpkgs-unstable 2.3.3 pkgs.terraform-providers.libvirt nixos-unstable ??? nixpkgs-unstable 0.8.3 pkgs.rubyPackages_3_1.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.rubyPackages_3_2.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.rubyPackages_3_3.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 pkgs.rubyPackages_3_4.ruby-libvirt nixos-unstable ??? nixpkgs-unstable 0.8.4 Package maintainers: 4 @farcaller Vladimir Pouzanov <farcaller@gmail.com> @globin Robin Gloster <mail@glob.in> @fpletz Franz Pletz <fpletz@fnordicwalking.de> @lovesegfault Bernardo Meurer <meurerbernardo@gmail.com>
pkgs.libvirt Toolkit to interact with the virtualization capabilities of recent versions of Linux and other OSes nixos-unstable ??? nixpkgs-unstable 11.6.0
pkgs.libvirt-glib Wrapper library of libvirt for glib-based applications nixos-unstable ??? nixpkgs-unstable 5.0.0
pkgs.prometheus-libvirt-exporter Prometheus metrics exporter for libvirt nixos-unstable ??? nixpkgs-unstable 2.3.3
CVE-2024-1545 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago Fault Injection of RSA encryption in WolfCrypt Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure. wolfssl =<5.6.6 pkgs.wolfssl Small, fast, portable implementation of TLS/SSL for embedded devices nixos-unstable ??? nixpkgs-unstable 5.8.2 Package maintainers: 2 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @vifino Adrian Pistol <vifino@tty.sh>
pkgs.wolfssl Small, fast, portable implementation of TLS/SSL for embedded devices nixos-unstable ??? nixpkgs-unstable 5.8.2
CVE-2024-43951 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 1 month, 1 week ago WordPress Tempera theme <= 1.8.2 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Tempera allows Stored XSS.This issue affects Tempera: from n/a through 1.8.2. tempera =<1.8.2 pkgs.home-assistant-component-tests.eddystone_temperature Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 Package maintainers: 3 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @dotlambda Robert Schütz <rschuetz17@gmail.com>
pkgs.home-assistant-component-tests.eddystone_temperature Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3