Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2020-37014
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored package tryton
  • @jopejoe1 dismissed
Tryton 5.4 - Persistent Cross-Site Scripting

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

Affected products

Tryton
  • =<5.4

Matching in nixpkgs

pkgs.trytond

Server of the Tryton application platform

Ignored packages (1)

pkgs.tryton

Client of the Tryton application platform

Package maintainers

Current stable was never impacted

https://github.com/NixOS/nixpkgs/commit/218c8509c6ce25945c2c253d15e9542033d4de44
Permalink CVE-2021-47908
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    6 packages
    • nnd
    • nim1
    • nim2
    • nim-2_0
    • lixStatic
    • nixStatic
  • @jopejoe1 dismissed
Ultimate POS 4.4 Persistent Cross-Site Scripting via Product Name

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.

Affected products

Unknown
  • ==4.4
Ignored packages (6)

pkgs.nim1

Statically typed, imperative programming language (x86_64-unknown-linux-gnu wrapper)

pkgs.nim2

Statically typed, imperative programming language (x86_64-unknown-linux-gnu wrapper)

pkgs.nim-2_0

Statically typed, imperative programming language (x86_64-unknown-linux-gnu wrapper)

Not present in nixpkgs
Permalink CVE-2026-2181
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored package go-crx3
  • @jopejoe1 dismissed
Tenda RX3 openSchedWifi stack-based overflow

A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

Affected products

RX3
  • ==16.03.13.11
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2026-2192
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored package vimPlugins.nvim-treesitter-parsers.kconfig
  • @jopejoe1 dismissed
Tenda AC9 formGetRebootTimer stack-based overflow

A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Affected products

AC9
  • ==15.03.06.42_multi
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2026-2187
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 dismissed
Tenda RX3 formSetQosBand set_qosMib_list stack-based overflow

A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Affected products

RX3
  • ==16.03.13.11

Matching in nixpkgs

Package maintainers

Not present in nixpkgs
Permalink CVE-2026-2191
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 dismissed
Tenda AC9 formGetDdosDefenceList stack-based overflow

A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

AC9
  • ==15.03.06.42_multi

Matching in nixpkgs

Not present in nixpkgs
Permalink CVE-2026-2185
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored package go-crx3
  • @jopejoe1 dismissed
Tenda RX3 MAC Filtering Configuration Endpoint setBlackRule set_device_name stack-based overflow

A flaw has been found in Tenda RX3 16.03.13.11. This issue affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. This manipulation of the argument devName/mac causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Affected products

RX3
  • ==16.03.13.11
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2026-2180
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @LeSuisse ignored package go-crx3
  • @jopejoe1 dismissed
Tenda RX3 fast_setting_wifi_set stack-based overflow

A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the argument ssid_5g leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.

Affected products

RX3
  • ==16.03.13.11
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47397
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 dismissed
Improper Release of Memory Before Removing Last Reference in Graphics

Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.

Affected products

Snapdragon
  • ==SA8195P
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==QPA1083BD
  • ==QAM8797P
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==WCN6755
  • ==SM8750P
  • ==LeMansAU
  • ==QMB415
  • ==QMP1000
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==QCA8695AU
  • ==SW6100
  • ==SD 8 Gen1 5G
  • ==SM7675
  • ==QLN1086BD
  • ==SA9000P
  • ==QCS4290
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==WCD9395
  • ==Vision Intelligence 400 Platform
  • ==QCM8838
  • ==SAR2230P
  • ==IQ9 Series Platform
  • ==QCA6698AQ
  • ==SA7255P
  • ==QLN1083BD
  • ==QAM8620P
  • ==QCN9011
  • ==TalynPlus
  • ==IQ10 Series
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==QCS6690
  • ==Themisto
  • ==SXR2350P
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==SSG2115P
  • ==SSG2125P
  • ==Monaco_IOT
  • ==SA8620P
  • ==QXM1096
  • ==SM6225P
  • ==QAM8255P
  • ==IQ8 Series Platform
  • ==Snapdragon 8 Elite
  • ==SW6100P
  • ==QPA1086BD
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FastConnect 7800
  • ==WCN6450
  • ==QCM2290
  • ==WCN7881
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==Snapdragon 8 Elite Gen 5
  • ==SA8155P
  • ==QCA6696
  • ==SRV1M
  • ==SA8770P
  • ==WSA8815
  • ==WCD9380
  • ==QCM6125
  • ==Orne
  • ==SA8295P
  • ==WSA8845H
  • ==QCA6797AQ
  • ==Snapdragon 7 Gen 4 Mobile Platform
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==WCD9335
  • ==WCN7860
  • ==Milos_IOT
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==SXR2250P
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==WCN7861
  • ==Palawan25
  • ==Snapdragon XR2 5G Platform
  • ==SA6155P
  • ==QCM6490
  • ==SW5100P
  • ==QCA6391
  • ==SAR1250P
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==QCS4490
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SDR753
  • ==SRV1H
  • ==SM6650P
  • ==WCD9370
  • ==Snapdragon AR1 Gen 1 Platform
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==QCA6574
  • ==QCA6595AU
  • ==QCM4325
  • ==QAM8295P
  • ==WSA8832
  • ==Snapdragon 680 4G Mobile Platform
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==WCN7880
  • ==QCS2290
  • ==SXR2230P
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==SAR2130P
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCM8550
  • ==QCN9274
  • ==QAMSRV1M
  • ==Robotics RB5 Platform
  • ==QCS8550
  • ==SXR2330P
  • ==QAMSRV1H
  • ==QAM8397P
  • ==SD865 5G
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==QMB715
  • ==IQ6 Series Platform
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==SXR1230P
  • ==WCD9375
  • ==WCD9378
  • ==FastConnect 6700
  • ==QXM1093
  • ==QCA6574AU
  • ==QXM1095
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==SRV1L
  • ==SA7775P
  • ==WCN3990
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==WSA8840
  • ==QXM1094
  • ==G2 Gen 1
  • ==Kalpeni
  • ==WCD9341
  • ==SM7675P
  • ==WSA8810
  • ==SM7635P
  • ==Pandeiro
  • ==QCM4490
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon 4 Gen 1 Mobile Platform

Matching in nixpkgs

Not present in nixpkgs
Permalink CVE-2025-47359
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 3 weeks ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored package snapdragon-profiler
  • @jopejoe1 dismissed
Use After Free in Secure Processor

Memory Corruption when multiple threads simultaneously access a memory free API.

Affected products

Snapdragon
  • ==WSA8835
  • ==QCC2072
  • ==WCD9385
  • ==XG101002
  • ==WSA8845
  • ==QCA6420
  • ==Snapdragon 8cx Compute Platform (SC8180XP-AC, AF) "Poipu Pro"
  • ==WSA8830
  • ==XG101032
  • ==QCA6391
  • ==SC8380XP
  • ==X2000077
  • ==FastConnect 6800
  • ==Snapdragon 8c Compute Platform (SC8180X-AD) "Poipu Lite"
  • ==X2000094
  • ==Snapdragon 8cx Compute Platform (SC8180X-AA, AB)
  • ==AQT1000
  • ==X2000086
  • ==WCD9378C
  • ==X2000092
  • ==FastConnect 7800
  • ==Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)
  • ==FastConnect 6900
  • ==XG101039
  • ==Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"
  • ==FastConnect 6200
  • ==WSA8840
  • ==X2000090
  • ==Snapdragon 8cx Gen 2 5G Compute Platform (SC8180X-AC, AF) "Poipu Pro"
  • ==QCA6430
  • ==WCD9341
  • ==Snapdragon 8cx Gen 2 5G Compute Platform (SC8180XP-AA, AB)
  • ==WSA8810
  • ==WSA8815
  • ==WCD9380
  • ==WCD9340
  • ==WSA8845H
Ignored packages (1)
Not present in nixpkgs