Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month ago
asterisk allows calls on prohibited networks

asterisk allows calls on prohibited networks

Affected products

asterisk
  • ==All 1.6.1 versions

Matching in nixpkgs

pkgs.asterisk_18

Software implementation of a telephone private branch exchange (PBX)

Package maintainers

created 1 month ago
Use after free vulnerability in documentloader in WebKit in Google …

Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDocument function.

Affected products

Chrome
  • ==before Blink M13

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
The git-changelog utility in git-extras 1.7.0 allows local users to …

The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.

Affected products

git-extras
  • ==1.7.0

Matching in nixpkgs

Package maintainers

created 1 month ago
offlineimap before 6.3.2 does not check for SSL server certificate …

offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.

References

Affected products

offlineimap
  • ==before 6.3.2

Matching in nixpkgs

pkgs.offlineimap

Synchronize emails between two repositories, so that you can read the same mailbox from multiple computers

created 1 month ago
ytnef has directory traversal

ytnef has directory traversal

References

Affected products

ytnef
  • ==through 2009-09-07 (Fixed In Version: 2.8)

Matching in nixpkgs

Package maintainers

created 1 month ago
Mozilla Firefox prior to 3.6 has a DoS vulnerability due …

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

References

Affected products

Firefox
  • ==prior to 3.6

Matching in nixpkgs

Package maintainers

created 1 month ago
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers …

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

References

Affected products

tahoe-lafs
  • ==1.10.0-2

Matching in nixpkgs

Package maintainers

created 1 month ago
A stale layout root is set as an input element …

A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.

References

Affected products

Chrome
  • ==before Blink M13

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
foomatic-rip filter, all versions, used insecurely creates temporary files for …

foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

Affected products

foomatic-filters
  • ==all versions

Matching in nixpkgs

Package maintainers

created 1 month ago
Incorrect handling of timer information in Timer.cpp in WebKit in …

Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.

Affected products

Chrome
  • ==before Blink M13

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin