CVE-2024-31253 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago WordPress WP OAuth Server (OAuth Authentication) plugin <= 4.3.3 - Open Redirection vulnerability URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3. Affected products oauth2-provider =<4.3.3 Matching in nixpkgs pkgs.haskellPackages.hoauth2-providers OAuth2 Identity Providers nixos-unstable ??? nixpkgs-unstable 0.8.0
pkgs.haskellPackages.hoauth2-providers OAuth2 Identity Providers nixos-unstable ??? nixpkgs-unstable 0.8.0
CVE-2024-3446 8.2 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months ago Qemu: virtio: dma reentrancy issue leads to double free vulnerability A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or allow arbitrary code execution within the context of the QEMU process on the host. Affected products qemu qemu-kvm virt:rhel * qemu-kvm-ma virt-devel:rhel * virt:av/qemu-kvm virt:rhel/qemu-kvm Matching in nixpkgs pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable ??? nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07 pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3 Package maintainers: 11 @oxalica oxalica <oxalicc@pm.me> @DavHau David Hauer <d.hauer.it@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net> @digitalrane Rane <rane+git@junkyard.systems> @CertainLach Yaroslav Bolyukin <iam@lach.pw> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable ??? nixpkgs-unstable 10.1.0
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_defconfig-2025.07
pkgs.ubootQemuX86_64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable x86_64_defconfig-2025.07
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable ??? nixpkgs-unstable qemu_arm64_defconfig-2025.07
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable ??? nixpkgs-unstable 2.13.0
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python313Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable ??? nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python313Packages.qemu-qmp Asyncio library for communicating with QEMU Monitor Protocol (“QMP”) servers nixos-unstable ??? nixpkgs-unstable 0.0.3
CVE-2024-1233 7.3 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 3 months ago Jboss eap: wildfly-elytron has a ssrf security issue A flaw was found in` JwtValidator.resolvePublicKey` in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability. Affected products eap wildfly <32.0.0.Final eap7-netty * eap7-wss4j * eap7-wildfly * eap7-undertow * eap7-hibernate * eap7-apache-cxf * eap7-infinispan * eap7-hal-console * eap8-elytron-web * eap7-glassfish-el * eap7-jackson-core * eap7-xml-security * eap7-jboss-modules * eap7-jboss-metadata * eap7-wildfly-elytron * eap7-wildfly-openssl * eap8-wildfly-elytron * eap7-jackson-databind * eap7-jboss-ejb-client * eap7-wildfly-discovery * eap7-jackson-annotations * eap7-wildfly-http-client * eap7-jackson-modules-base * eap7-jackson-modules-java8 * eap7-wildfly-naming-client * eap7-wildfly-openssl-linux * eap7-jboss-jsf-api_2.3_spec * eap7-jboss-server-migration * eap7-jackson-jaxrs-providers * eap7-wildfly-transaction-client * org.wildfly.security/wildfly-elytron * Matching in nixpkgs pkgs.reap Run process until all its spawned processes are dead nixos-unstable ??? nixpkgs-unstable 0.3-unreleased pkgs.leaps Pair programming tool and library written in Golang nixos-unstable ??? nixpkgs-unstable 0.9.1 pkgs.asleap Recovers weak LEAP and PPTP passwords nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-06-20 pkgs.reaper Digital audio workstation nixos-unstable ??? nixpkgs-unstable 7.45 pkgs.teapot Table Editor And Planner, Or: Teapot nixos-unstable ??? nixpkgs-unstable 2.3.0 pkgs.adreaper Enumeration tool for Windows Active Directories nixos-unstable ??? nixpkgs-unstable 1.1 pkgs.heaptrack Heap memory profiler for Linux nixos-unstable ??? nixpkgs-unstable 1.5.0-unstable-2025-07-21 pkgs.reaper-go Application security testing framework nixos-unstable ??? nixpkgs-unstable 0.2.3 pkgs.input-leap Open-source KVM software nixos-unstable ??? nixpkgs-unstable 3.0.3 pkgs.tuleap-cli Command-line interface for the Tuleap API nixos-unstable ??? nixpkgs-unstable 1.2.0 pkgs.libfreeaptx Free Implementation of Audio Processing Technology codec (aptX) nixos-unstable ??? nixpkgs-unstable 0.2.2 pkgs.sbclPackages.heap nixos-unstable ??? nixpkgs-unstable 20181018-git pkgs.haxePackages.heaps GPU game framework nixos-unstable ??? nixpkgs-unstable 1.9.1 pkgs.pineapple-pictures Homebrew lightweight image viewer nixos-unstable ??? nixpkgs-unstable 1.1.1 pkgs.haskellPackages.eap Extensible Authentication Protocol (EAP) nixos-unstable ??? nixpkgs-unstable 0.9.0.2 pkgs.haskellPackages.heap Heaps in Haskell nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.reaper-sws-extension Reaper Plugin Extension nixos-unstable ??? nixpkgs-unstable 2.14.0.3 pkgs.sbclPackages.cl-heap nixos-unstable ??? nixpkgs-unstable 0.1.6 pkgs.sbclPackages.minheap nixos-unstable ??? nixpkgs-unstable 20160628-git pkgs.haskellPackages.heaps Asymptotically optimal Brodal/Okasaki heaps nixos-unstable ??? nixpkgs-unstable 0.4.1 pkgs.akkuPackages.pfds-heap Heap data structure nixos-unstable ??? nixpkgs-unstable 1.0.0 pkgs.luaPackages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1 pkgs.python312Packages.deap Novel evolutionary computation framework for rapid prototyping and testing of ideas nixos-unstable ??? nixpkgs-unstable 1.4.3 pkgs.python313Packages.deap Novel evolutionary computation framework for rapid prototyping and testing of ideas nixos-unstable ??? nixpkgs-unstable 1.4.3 pkgs.gnomeExtensions.ideapad Lenovo IdeaPad goodies for Gnome Shell nixos-unstable ??? nixpkgs-unstable 20 pkgs.haskellPackages.heapsize Determine the size of runtime data structures nixos-unstable ??? nixpkgs-unstable 0.3.0.1 pkgs.lua51Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1 pkgs.lua52Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1 pkgs.lua53Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1 pkgs.lua54Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1 pkgs.python312Packages.pyeapi Client for Arista eAPI nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.python313Packages.pyeapi Client for Arista eAPI nixos-unstable ??? nixpkgs-unstable 1.0.4 pkgs.reaper-reapack-extension Package manager for REAPER nixos-unstable ??? nixpkgs-unstable 1.2.5 pkgs.luajitPackages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1 pkgs.python312Packages.coreapi Python client library for Core API nixos-unstable ??? nixpkgs-unstable 2.3.3 pkgs.haskellPackages.cheapskate Experimental markdown processor nixos-unstable ??? nixpkgs-unstable 0.1.1.2 pkgs.perlPackages.HeapFibonacci Perl extensions for keeping data partially sorted nixos-unstable ??? nixpkgs-unstable 0.80 pkgs.python312Packages.heapdict Heap with decrease-key and increase-key operations nixos-unstable ??? nixpkgs-unstable 1.0.1 pkgs.python313Packages.heapdict Heap with decrease-key and increase-key operations nixos-unstable ??? nixpkgs-unstable 1.0.1 pkgs.sbclPackages.binomial-heap nixos-unstable ??? nixpkgs-unstable 20130420-git pkgs.python312Packages.jaydebeapi Use JDBC database drivers from Python 2/3 or Jython with a DB-API nixos-unstable ??? nixpkgs-unstable 1.2.3 pkgs.python313Packages.jaydebeapi Use JDBC database drivers from Python 2/3 or Jython with a DB-API nixos-unstable ??? nixpkgs-unstable 1.2.3 pkgs.haskellPackages.ghc-heap-view Extract the heap representation of Haskell values and thunks nixos-unstable ??? nixpkgs-unstable 0.6.4.1 pkgs.haskellPackages.meldable-heap Asymptotically optimal, Coq-verified meldable heaps, AKA priority queues nixos-unstable ??? nixpkgs-unstable 2.0.3 pkgs.perl538Packages.HeapFibonacci Perl extensions for keeping data partially sorted nixos-unstable ??? nixpkgs-unstable 0.80 pkgs.perl540Packages.HeapFibonacci Perl extensions for keeping data partially sorted nixos-unstable ??? nixpkgs-unstable 0.80 pkgs.python312Packages.pynamecheap Namecheap API client in Python nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.python313Packages.pynamecheap Namecheap API client in Python nixos-unstable ??? nixpkgs-unstable 0.0.3 pkgs.terraform-providers.namecheap nixos-unstable ??? nixpkgs-unstable 2.2.0 pkgs.python312Packages.tami4edgeapi Python API client for Tami4 Edge / Edge+ devices nixos-unstable ??? nixpkgs-unstable tami4edgeapi-3.0 pkgs.python313Packages.tami4edgeapi Python API client for Tami4 Edge / Edge+ devices nixos-unstable ??? nixpkgs-unstable tami4edgeapi-3.0 pkgs.python312Packages.aioesphomeapi Python Client for ESPHome native API nixos-unstable ??? nixpkgs-unstable 39.0.1 pkgs.python313Packages.aioesphomeapi Python Client for ESPHome native API nixos-unstable ??? nixpkgs-unstable 39.0.1 pkgs.gnomeExtensions.ideapad-controls Control Lenovo IdeaPad laptops options: Conservation Mode, Camera Lock, Fn Lock, Touchpad Lock, USB charging nixos-unstable ??? nixpkgs-unstable 3 pkgs.haskellPackages.cheapskate-lucid Use cheapskate with Lucid nixos-unstable ??? nixpkgs-unstable 0.1.0.0 pkgs.gnomeExtensions.transcodeappsearch Searching apps both direct and transcoded name (English, Russian, Ukrainian langs) nixos-unstable ??? nixpkgs-unstable 19 pkgs.rubyPackages.jekyll-theme-leap-day nixos-unstable ??? nixpkgs-unstable 0.1.1 pkgs.azure-cli-extensions.healthcareapis Microsoft Azure Command-Line Tools HealthcareApisManagementClient Extension nixos-unstable ??? nixpkgs-unstable 1.0.1 pkgs.haskellPackages.leapseconds-announced Leap seconds announced at library release time nixos-unstable ??? nixpkgs-unstable 2017.1.0.1 pkgs.rubyPackages_3_1.jekyll-theme-leap-day nixos-unstable ??? nixpkgs-unstable 0.1.1 pkgs.rubyPackages_3_2.jekyll-theme-leap-day nixos-unstable ??? nixpkgs-unstable 0.1.1 pkgs.rubyPackages_3_3.jekyll-theme-leap-day nixos-unstable ??? nixpkgs-unstable 0.1.1 pkgs.rubyPackages_3_4.jekyll-theme-leap-day nixos-unstable ??? nixpkgs-unstable 0.1.1 pkgs.home-assistant-component-tests.spaceapi Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 pkgs.kubernetes-helmPlugins.helm-mapkubeapis Helm plugin which maps deprecated or removed Kubernetes APIs in a release to supported APIs nixos-unstable ??? nixpkgs-unstable 0.6.1 pkgs.chickenPackages_5.chickenEggs.binary-heap Binary heap. nixos-unstable ??? nixpkgs-unstable 2.2 pkgs.chickenPackages_5.chickenEggs.heap-o-rama ... nixos-unstable ??? nixpkgs-unstable 0.4 pkgs.python312Packages.googleapis-common-protos Common protobufs used in Google APIs nixos-unstable ??? nixpkgs-unstable 3.31.3 pkgs.python313Packages.googleapis-common-protos Common protobufs used in Google APIs nixos-unstable ??? nixpkgs-unstable 3.31.3 pkgs.home-assistant-component-tests.namecheapdns Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3 pkgs.typstPackages.cyberschool-errorteaplate_0_1_3 This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school nixos-unstable ??? nixpkgs-unstable 0.1.3 pkgs.typstPackages.cyberschool-errorteaplate_0_1_4 This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school nixos-unstable ??? nixpkgs-unstable 0.1.4 pkgs.typstPackages.cyberschool-errorteaplate_0_1_5 This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school nixos-unstable ??? nixpkgs-unstable 0.1.5 Package maintainers: 37 @phryneas Lenz Weber <mail@lenzw.de> @KoviRobi Kovacsics Robert <kovirobi@gmail.com> @shymega Dom Rodriguez @Twey James ‘Twey’ Kay <twey@twey.co.uk> @honnip Jung seungwoo <me@honnip.page> @JamieMagee Jamie Magee <jamie.magee@gmail.com> @pyrox0 Pyrox <pyrox@pyrox.dev> @ulrikstrid Ulrik Strid <ulrik.strid@outlook.com> @katexochen Paul Meyer <katexochen0@gmail.com> @vcunat Vladimír Čunát <v@cunat.cz> @nagy Daniel Nagy <danielnagy@posteo.de> @Uthar Kasper Gałkowski <galkowskikasper@gmail.com> @lukego Luke Gorrie <luke@snabb.co> @hraban Hraban Luyat <hraban@0brg.net> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @GetPsyched Priyanshu Tripathi <nixos@getpsyched.dev> @PsyanticY Psyanticy <iuns@outlook.fr> @fabaff Fabian Affolter <mail@fabian-affolter.ch> @mweinelt Martin Weinelt <hexa@darmstadt.ccc.de> @dotlambda Robert Schütz <rschuetz17@gmail.com> @teh Tom Hunger <tehunger@gmail.com> @astro Astro <astro@spaceboyz.net> @Kranzes Ilan Joselevich <personal@ilanjoselevich.com> @aos aos <n@aos.sh> @sarahec Sarah Clark <seclark@nextquestion.net> @leahneukirchen Leah Neukirchen <leah@vuxu.org> @viraptor Stanisław Pitucha <nix@viraptor.info> @orivej Orivej Desh <orivej@gmx.fr> @uniquepointer uniquepointer <uniquepointer@mailbox.org> @atinba Atin Bainada @ilian ilian <nixos@ilian.dev> @pancaek paneku @t4ccer Tomasz Maciosowski <t4ccer@gmail.com> @qknight Joachim Schiele <js@lastlog.de> @wineee Lu Hongxu <lhongxu@outlook.com> @cherrypiejam Gongqi Huang @LeSuisse Thomas Gerbet <thomas@gerbet.me>
pkgs.reap Run process until all its spawned processes are dead nixos-unstable ??? nixpkgs-unstable 0.3-unreleased
pkgs.leaps Pair programming tool and library written in Golang nixos-unstable ??? nixpkgs-unstable 0.9.1
pkgs.asleap Recovers weak LEAP and PPTP passwords nixos-unstable ??? nixpkgs-unstable 0-unstable-2021-06-20
pkgs.adreaper Enumeration tool for Windows Active Directories nixos-unstable ??? nixpkgs-unstable 1.1
pkgs.heaptrack Heap memory profiler for Linux nixos-unstable ??? nixpkgs-unstable 1.5.0-unstable-2025-07-21
pkgs.libfreeaptx Free Implementation of Audio Processing Technology codec (aptX) nixos-unstable ??? nixpkgs-unstable 0.2.2
pkgs.haskellPackages.eap Extensible Authentication Protocol (EAP) nixos-unstable ??? nixpkgs-unstable 0.9.0.2
pkgs.haskellPackages.heaps Asymptotically optimal Brodal/Okasaki heaps nixos-unstable ??? nixpkgs-unstable 0.4.1
pkgs.luaPackages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1
pkgs.python312Packages.deap Novel evolutionary computation framework for rapid prototyping and testing of ideas nixos-unstable ??? nixpkgs-unstable 1.4.3
pkgs.python313Packages.deap Novel evolutionary computation framework for rapid prototyping and testing of ideas nixos-unstable ??? nixpkgs-unstable 1.4.3
pkgs.gnomeExtensions.ideapad Lenovo IdeaPad goodies for Gnome Shell nixos-unstable ??? nixpkgs-unstable 20
pkgs.haskellPackages.heapsize Determine the size of runtime data structures nixos-unstable ??? nixpkgs-unstable 0.3.0.1
pkgs.lua51Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1
pkgs.lua52Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1
pkgs.lua53Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1
pkgs.lua54Packages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1
pkgs.luajitPackages.binaryheap Binary heap implementation in pure Lua nixos-unstable ??? nixpkgs-unstable 0.4-1
pkgs.python312Packages.coreapi Python client library for Core API nixos-unstable ??? nixpkgs-unstable 2.3.3
pkgs.haskellPackages.cheapskate Experimental markdown processor nixos-unstable ??? nixpkgs-unstable 0.1.1.2
pkgs.perlPackages.HeapFibonacci Perl extensions for keeping data partially sorted nixos-unstable ??? nixpkgs-unstable 0.80
pkgs.python312Packages.heapdict Heap with decrease-key and increase-key operations nixos-unstable ??? nixpkgs-unstable 1.0.1
pkgs.python313Packages.heapdict Heap with decrease-key and increase-key operations nixos-unstable ??? nixpkgs-unstable 1.0.1
pkgs.python312Packages.jaydebeapi Use JDBC database drivers from Python 2/3 or Jython with a DB-API nixos-unstable ??? nixpkgs-unstable 1.2.3
pkgs.python313Packages.jaydebeapi Use JDBC database drivers from Python 2/3 or Jython with a DB-API nixos-unstable ??? nixpkgs-unstable 1.2.3
pkgs.haskellPackages.ghc-heap-view Extract the heap representation of Haskell values and thunks nixos-unstable ??? nixpkgs-unstable 0.6.4.1
pkgs.haskellPackages.meldable-heap Asymptotically optimal, Coq-verified meldable heaps, AKA priority queues nixos-unstable ??? nixpkgs-unstable 2.0.3
pkgs.perl538Packages.HeapFibonacci Perl extensions for keeping data partially sorted nixos-unstable ??? nixpkgs-unstable 0.80
pkgs.perl540Packages.HeapFibonacci Perl extensions for keeping data partially sorted nixos-unstable ??? nixpkgs-unstable 0.80
pkgs.python312Packages.pynamecheap Namecheap API client in Python nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python313Packages.pynamecheap Namecheap API client in Python nixos-unstable ??? nixpkgs-unstable 0.0.3
pkgs.python312Packages.tami4edgeapi Python API client for Tami4 Edge / Edge+ devices nixos-unstable ??? nixpkgs-unstable tami4edgeapi-3.0
pkgs.python313Packages.tami4edgeapi Python API client for Tami4 Edge / Edge+ devices nixos-unstable ??? nixpkgs-unstable tami4edgeapi-3.0
pkgs.python312Packages.aioesphomeapi Python Client for ESPHome native API nixos-unstable ??? nixpkgs-unstable 39.0.1
pkgs.python313Packages.aioesphomeapi Python Client for ESPHome native API nixos-unstable ??? nixpkgs-unstable 39.0.1
pkgs.gnomeExtensions.ideapad-controls Control Lenovo IdeaPad laptops options: Conservation Mode, Camera Lock, Fn Lock, Touchpad Lock, USB charging nixos-unstable ??? nixpkgs-unstable 3
pkgs.haskellPackages.cheapskate-lucid Use cheapskate with Lucid nixos-unstable ??? nixpkgs-unstable 0.1.0.0
pkgs.gnomeExtensions.transcodeappsearch Searching apps both direct and transcoded name (English, Russian, Ukrainian langs) nixos-unstable ??? nixpkgs-unstable 19
pkgs.azure-cli-extensions.healthcareapis Microsoft Azure Command-Line Tools HealthcareApisManagementClient Extension nixos-unstable ??? nixpkgs-unstable 1.0.1
pkgs.haskellPackages.leapseconds-announced Leap seconds announced at library release time nixos-unstable ??? nixpkgs-unstable 2017.1.0.1
pkgs.home-assistant-component-tests.spaceapi Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3
pkgs.kubernetes-helmPlugins.helm-mapkubeapis Helm plugin which maps deprecated or removed Kubernetes APIs in a release to supported APIs nixos-unstable ??? nixpkgs-unstable 0.6.1
pkgs.python312Packages.googleapis-common-protos Common protobufs used in Google APIs nixos-unstable ??? nixpkgs-unstable 3.31.3
pkgs.python313Packages.googleapis-common-protos Common protobufs used in Google APIs nixos-unstable ??? nixpkgs-unstable 3.31.3
pkgs.home-assistant-component-tests.namecheapdns Open source home automation that puts local control and privacy first nixos-unstable ??? nixpkgs-unstable 2025.9.3
pkgs.typstPackages.cyberschool-errorteaplate_0_1_3 This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school nixos-unstable ??? nixpkgs-unstable 0.1.3
pkgs.typstPackages.cyberschool-errorteaplate_0_1_4 This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school nixos-unstable ??? nixpkgs-unstable 0.1.4
pkgs.typstPackages.cyberschool-errorteaplate_0_1_5 This is a template originaly made for the Cyberschool of Rennes, a Cybersecurity school nixos-unstable ??? nixpkgs-unstable 0.1.5
CVE-2024-31308 4.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 3 months ago WordPress WP Import Export Lite & WP Import Export plugin <= 3.9.26 - PHP Object Injection vulnerability Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26. Affected products wp-import-export-lite =<3.9.26 Matching in nixpkgs pkgs.wordpressPackages.plugins.wp-import-export-lite nixos-unstable ??? nixpkgs-unstable 3.9.28
CVE-2024-31083 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months ago Xorg-x11-server: user-after-free in procrenderaddglyphs A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request. Affected products tigervnc * xorg-x11-server ==21.1.12 * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
CVE-2024-2312 6.7 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 months ago GRUB2 does not call the module fini functions on exit, … GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass. Affected products grub2 <2.12-1ubuntu5 Matching in nixpkgs pkgs.grub2_pvgrub_image PvGrub2 image for booting PV Xen guests nixos-unstable ??? nixpkgs-unstable pkgs.grub2_pvhgrub_image PvGrub2 image for booting PVH Xen guests nixos-unstable ??? nixpkgs-unstable Package maintainers: 4 @hehongbo Hongbo @digitalrane Rane <rane+git@junkyard.systems> @CertainLach Yaroslav Bolyukin <iam@lach.pw> @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net>
pkgs.grub2_pvhgrub_image PvGrub2 image for booting PVH Xen guests nixos-unstable ??? nixpkgs-unstable
CVE-2024-31080 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): HIGH created 3 months ago Xorg-x11-server: heap buffer overread/data leakage in procxigetselectedevents A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads. Affected products tigervnc * xorg-server * xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
CVE-2024-3296 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 months ago Rust-openssl: timing based side-channel can lead to a bleichenbacher style attack A timing-based side-channel exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages for decryption. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode. Affected products bootc 389-ds-base rust-bootupd rust-openssl * rust-zincati keylime-agent-rust 389-ds:1.4/389-ds-base python3.12-cryptography 389-directory-server:next/389-ds-base 389-directory-server:stable/389-ds-base 389-directory-server:testing/389-ds-base Matching in nixpkgs pkgs.bootc Boot and upgrade via container images nixos-unstable ??? nixpkgs-unstable 1.6.0 pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3 pkgs.podman-bootc Streamlining podman+bootc interactions nixos-unstable ??? nixpkgs-unstable 0.1.2 pkgs.mlxbf-bootctl Control BlueField boot partitions nixos-unstable ??? nixpkgs-unstable 2025-01-16 pkgs.systemd-bootchart Boot performance graphing tool from systemd nixos-unstable ??? nixpkgs-unstable 235 pkgs.python312Packages.cryptography Package which provides cryptographic recipes and primitives nixos-unstable ??? nixpkgs-unstable 45.0.4 Package maintainers: 7 @evan-goode Evan Goode <mail@evangoo.de> @nikstur nikstur <nikstur@outlook.com> @thillux Markus Theil <theil.markus@gmail.com> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @Thesola10 Karim Vergnes <me@thesola.io> @SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com> @ners ners <ners@gmx.ch>
pkgs._389-ds-base Enterprise-class Open Source LDAP server for Linux nixos-unstable ??? nixpkgs-unstable 3.1.3
pkgs.systemd-bootchart Boot performance graphing tool from systemd nixos-unstable ??? nixpkgs-unstable 235
pkgs.python312Packages.cryptography Package which provides cryptographic recipes and primitives nixos-unstable ??? nixpkgs-unstable 45.0.4
CVE-2024-31081 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): HIGH created 3 months ago Xorg-x11-server: heap buffer overread/data leakage in procxipassivegrabdevice A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads. Affected products tigervnc * xorg-server ==1.7.0 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
CVE-2024-31082 7.3 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): LOW Availability impact (A): HIGH created 3 months ago Xorg-x11-server: heap buffer overread/data leakage in procappledricreatepixmap A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads. Affected products tigervnc xorg-server <21.1.12 xorg-x11-server xorg-x11-server-Xwayland Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable ??? nixpkgs-unstable 1.15.0