CVE-2023-5546 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Moodle: stored xss in quiz grading report via user id number ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Affected products moodle <4.2.3 <4.0.11 <4.1.6 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-5543 3.3 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Moodle: duplicating a bigbluebutton activity assigns the same meeting id When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting. Affected products moodle <4.2.3 <4.0.11 <4.1.6 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-23457 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Upx: segv on packlinuxelf64::invert_pt_dynamic() in p_lx_elf.cpp A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. Affected products upx * Matching in nixpkgs pkgs.upx Ultimate Packer for eXecutables nixos-unstable ??? nixpkgs-unstable 5.0.2
CVE-2023-5539 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Moodle: authenticated remote code execution risk in lesson A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. Affected products moodle <4.0.11 <4.2.3 <4.1.6 <3.9.24 <3.11.17 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-35133 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Moodle: ssrf risk due to insufficient check on the curl blocked hosts An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions. Affected products moodle <4.1.4 <4.0.9 <3.11.15 <3.9.22 <4.2.1 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-28330 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Moodle: authenticated arbitrary file read through malformed backup file Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default. Affected products moodle <4.0.7 <3.11.13 <3.9.20 <4.1.2 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-35131 6.1 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago Moodle: xss risk on groups page Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14. Affected products moodle <4.1.4 <4.2.1 <3.11.15 <4.0.9 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-5540 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Moodle: authenticated remote code execution risk in imscp A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. Affected products moodle <4.0.11 <4.2.3 <4.1.6 <3.9.24 <3.11.17 Matching in nixpkgs pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2 pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13 Package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-unstable ??? nixpkgs-unstable 5.0.2
pkgs.moodle-dl Moodle downloader that downloads course content fast from Moodle nixos-unstable ??? nixpkgs-unstable 2.3.13
CVE-2023-1544 6.0 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 3 months ago Qemu: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a huge number of page tables to be used as a ring of descriptors for CQ and async events, potentially leading to an out-of-bounds read and crash of QEMU. Affected products qemu * Matching in nixpkgs pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07 pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 Package maintainers: 11 @oxalica oxalica <oxalicc@pm.me> @DavHau David Hauer <d.hauer.it@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net> @digitalrane Rane <rane+git@junkyard.systems> @CertainLach Yaroslav Bolyukin <iam@lach.pw> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07
pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
CVE-2023-23456 5.3 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Upx: heap-buffer-overflow in packtmt::pack() A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. Affected products upx * Matching in nixpkgs pkgs.upx Ultimate Packer for eXecutables nixos-unstable ??? nixpkgs-unstable 5.0.2