Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month ago
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable …

Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

Affected products

netsurf
  • ==through 2.8

Matching in nixpkgs

pkgs.netsurf.libcss

Cascading Style Sheets library for netsurf browser

pkgs.netsurf.libdom

Document Object Model library for netsurf browser

Package maintainers

created 1 month ago
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete …

Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

Affected products

Tahoe-LAFS
  • ==v1.3.0 through v1.8.2

Matching in nixpkgs

Package maintainers

created 1 month ago
systemd 37-1 does not properly handle non-existent services, which causes …

systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure).

Affected products

systemd
  • ==37-1

Matching in nixpkgs

created 1 month ago
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows …

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

References

Affected products

Konqueror
  • ==4.7.3

Matching in nixpkgs

Package maintainers

updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    10 packages
    • jenkins-job-builder
    • python312Packages.jenkinsapi
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python312Packages.python-jenkins
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python312Packages.jenkins-job-builder
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS …

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

Affected products

jenkins
  • ==2

Matching in nixpkgs

Ignored packages (10)

Package maintainers

created 1 month ago
LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in …

LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny.

Affected products

Mint
  • ==2012-03-19

Matching in nixpkgs

pkgs.garmintools

Provides the ability to communicate with the Garmin Forerunner 305 via the USB interface

pkgs.marwaita-mint

Variation for marwaita GTK theme based on linux mint color scheme

  • nixos-unstable 24
    • nixpkgs-unstable 24
    • nixos-unstable-small 24
  • nixos-25.11 24
    • nixos-25.11-small 24
    • nixpkgs-25.11-darwin 24

Package maintainers

created 1 month ago
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure …

Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.

References

Affected products

Magento
  • ==fixed in 1.7.0.2
  • ==1.7.0.1

Matching in nixpkgs

Package maintainers

created 1 month ago
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) …

rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started.

References

Affected products

rpcbind
  • ==0.2.0

Matching in nixpkgs

Package maintainers

created 1 month ago
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting …

OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space

Affected products

Keystone
  • ==2014.1.3

Matching in nixpkgs

Package maintainers

created 1 month ago
Mercurial before 1.6.4 fails to verify the Common Name field …

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.

Affected products

mercurial
  • ==1.6.4

Matching in nixpkgs

pkgs.mercurial

Fast, lightweight SCM system for very large distributed projects

Package maintainers