Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: winetricks

Found 2 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-82478
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): Not Defined (X)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 2 weeks, 2 days ago Activity log
  • Created suggestion
NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow

A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Trick
  • ==19.6.0

Matching in nixpkgs

pkgs.pdftricks

Simple, efficient application for small manipulations in PDF files using Ghostscript

pkgs.trickster

Reverse proxy cache and time series dashboard accelerator

pkgs.gnomeExtensions.window-tricks

Focus, snap, switch and resize windows with keybinds, clipboard history indicator and app tray indicator.

  • nixos-unstable 10
    • nixpkgs-unstable 10
    • nixos-unstable-small 10
  • nixos-26.05 10
    • nixos-26.05-small 10
    • nixpkgs-26.05-darwin 10

Package maintainers

Permalink CVE-2026-48831
7.3 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Automatable (AU): No (N)
  • Value Density (V): Diffuse (D)
  • Provider Urgency (U): Clear (Clear)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 months, 3 weeks ago Activity log
  • Created suggestion
Wine ships a .desktop file that registers itself as a …

Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions of the invoker. This allows escaping Flatpak and Snap sandboxes, because MIME handlers are not intended for use by code interpreters and loaders. NOTE: some parties feel that this is not a bug to be addressed in Wine, because there is no known solution that avoids a severe loss of usability (Wine could be a binfmt-misc handler, but binfmt-misc does not exist on all platforms supported by Wine).

Affected products

Wine
  • =<11.0

Matching in nixpkgs

pkgs.twine

Collection of utilities for interacting with PyPI

pkgs.q4wine

Qt GUI for Wine to manage prefixes and applications

pkgs.wine64

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.entwine

Point cloud organization for massive datasets

pkgs.twinejs

Open-source tool for telling interactive, nonlinear stories

pkgs.wineasio

ASIO to JACK driver for WINE

pkgs.wine.x86_64-linux

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wine64Packages.base

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wine64Packages.full

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wine64Packages.stable

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wine64Packages.minimal

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wine64Packages.staging

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-unstable 11.8
    • nixpkgs-unstable 11.8
    • nixos-unstable-small 11.8

pkgs.wine64Packages.wayland

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wineWow64Packages.base

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wineWow64Packages.full

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0

pkgs.wine-staging.x86_64-linux

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-unstable 11.8
    • nixpkgs-unstable 11.8
    • nixos-unstable-small 11.8

pkgs.wineWow64Packages.staging

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-unstable 11.8
    • nixpkgs-unstable 11.8
    • nixos-unstable-small 11.8

pkgs.wine64Packages.stagingFull

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-unstable 11.8
    • nixpkgs-unstable 11.8
    • nixos-unstable-small 11.8

Package maintainers