Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2026-3967
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    11 packages
    • libsForQt5.kactivities
    • plasma5Packages.kactivities
    • libsForQt5.kactivities-stats
    • kdePackages.plasma-activities
    • gnomeExtensions.auto-activities
    • gnomeExtensions.logo-activities
    • plasma5Packages.kactivities-stats
    • kdePackages.plasma-activities-stats
    • gnomeExtensions.hide-activities-button
    • gnomeExtensions.middle-click-activities
    • gnomeExtensions.double-click-activities-to-app-grid
  • @LeSuisse dismissed
Alfresco Activiti Process Variable Serialization System SerializableType.java createObjectInputStream deserialization

A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization System. This manipulation causes deserialization. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Activiti
  • ==8.0
  • ==7.10
  • ==7.17
  • ==7.15
  • ==8.6
  • ==7.9
  • ==7.1
  • ==8.3
  • ==7.4
  • ==8.8.0
  • ==8.7
  • ==7.8
  • ==7.14
  • ==7.11
  • ==7.16
  • ==8.5
  • ==7.19
  • ==7.0
  • ==7.12
  • ==7.18
  • ==7.13
  • ==7.3
  • ==8.4
  • ==7.5
  • ==8.2
  • ==7.2
  • ==8.1
  • ==7.7
  • ==7.6
Ignored packages (11)

pkgs.gnomeExtensions.auto-activities

Show activities overview when there are no windows, or hide it when there are new windows.

  • nixos-unstable 16
    • nixpkgs-unstable 16
    • nixos-unstable-small 16
  • nixos-25.11 16
    • nixos-25.11-small 16
    • nixpkgs-25.11-darwin 16

pkgs.gnomeExtensions.hide-activities-button

Hides the Activities button from the status bar (the hot corner and keyboard shortcut keeps working). To disable top left hot corner use 'No Topleft Hot Corner' extension — https://extensions.gnome.org/extension/118/no-topleft-hot-corner/ .

  • nixos-unstable 22
    • nixpkgs-unstable 22
    • nixos-unstable-small 22
  • nixos-25.11 22
    • nixos-25.11-small 22
    • nixpkgs-25.11-darwin 22
Not present in nixpkgs