Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2026-3976
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    35 packages
    • gaw
    • w3m
    • Xaw3d
    • pw3270
    • revpfw3
    • w3m-nox
    • libxaw3d
    • w3m-full
    • sparrow3d
    • w3m-batch
    • libgtkflow3
    • w3m-nographics
    • python312Packages.w3lib
    • python313Packages.w3lib
    • python314Packages.w3lib
    • tests.fetchzip.postFetch
    • perlPackages.W3CLinkChecker
    • perl5Packages.W3CLinkChecker
    • tests.fetchurl.hashedMirrors
    • tests.fetchgit.sparseCheckout
    • perl538Packages.W3CLinkChecker
    • perl540Packages.W3CLinkChecker
    • tests.fetchFromGitHub.leave-git
    • perlPackages.DateTimeFormatW3CDTF
    • ocamlPackages.lablgtk3-sourceview3
    • perl5Packages.DateTimeFormatW3CDTF
    • chickenPackages_5.chickenEggs.glfw3
    • perl538Packages.DateTimeFormatW3CDTF
    • perl540Packages.DateTimeFormatW3CDTF
    • perlPackages.WebServiceValidatorHTMLW3C
    • perl5Packages.WebServiceValidatorHTMLW3C
    • ocamlPackages_latest.lablgtk3-sourceview3
    • perl538Packages.WebServiceValidatorHTMLW3C
    • perl540Packages.WebServiceValidatorHTMLW3C
    • haskellPackages.hs-opentelemetry-propagator-w3c
  • @LeSuisse dismissed
Tenda W3 POST Parameter WifiMacFilterSet formWifiMacFilterSet stack-based overflow

A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

W3
  • ==1.0.0.3(2204)
Ignored packages (35)

pkgs.w3m

Text-mode web browser

pkgs.Xaw3d

3D widget set based on the Athena Widget set

pkgs.revpfw3

Reverse proxy to bypass the need for port forwarding

pkgs.libxaw3d

3D appearance variant of the X Athena Widget Set

Not present in nixpkgs