Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2010-0047
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month ago
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows …

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."

References

Affected products

n/a
  • ==n/a
safari
  • ==4.0.2
  • ==4.0.0b
  • =<4.0.4
  • ==4.0.3
  • ==4.0.1
  • ==4.0

Matching in nixpkgs

created 1 month ago
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

References

Affected products

gnome-keyring
  • ==Fixed 3.14.0

Matching in nixpkgs

pkgs.gnome-keyring

Collection of components in GNOME that store secrets, passwords, keys, certificates and make them available to applications

Package maintainers

created 1 month ago
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible …

The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.

Affected products

unixodbc
  • ==before 2.2.14p2

Matching in nixpkgs

created 1 month ago
An integer overflow condition in poppler before 0.16.3 can occur …

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

References

Affected products

poppler
  • ==before 0.16.3

Matching in nixpkgs

Package maintainers

created 1 month ago
Insufficient policy enforcement in V8 in Google Chrome prior to …

Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

References

Affected products

Chrome
  • <14.0.0.0

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
PackageKit 0.6.17 allows installation of unsigned RPM packages as though …

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.

Affected products

packagekit
  • ==0.6.15
  • ==0.6.17

Matching in nixpkgs

Package maintainers

created 1 month ago
Yaws 1.91 has a directory traversal vulnerability in the way …

Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.

Affected products

yaws
  • ==1.91

Matching in nixpkgs

created 1 month ago
liboping 1.3.2 allows users reading arbitrary files upon the local …

liboping 1.3.2 allows users reading arbitrary files upon the local system.

Affected products

liboping
  • ==1.3.2

Matching in nixpkgs

Package maintainers

created 1 month ago
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted …

Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.

Affected products

polipo
  • ==before 1.0.4.1

Matching in nixpkgs

pkgs.polipo

Small and fast caching web proxy

Package maintainers

created 1 month ago
Transmission before 1.92 allows attackers to prevent download of a …

Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.

References

Affected products

transmission
  • ==before 1.92

Matching in nixpkgs

pkgs.transmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.libtransmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.transmission_3-qt

Fast, easy and free BitTorrent client (deprecated version 3)

Package maintainers