Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month ago
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome …

An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.

Affected products

Chrome
  • ==before Blink M11 and M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
lightdm before 0.9.6 writes in .dmrc and Xauthority files using …

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

References

Affected products

lightdm
  • ==before 0.9.6

Matching in nixpkgs

Package maintainers

created 1 month ago
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal …

The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.

References

Affected products

BrowserID
  • ==7.x-1.x before 7.x-1.3

Matching in nixpkgs

created 1 month ago
atop: symlink attack possible due to insecure tempfile handling

atop: symlink attack possible due to insecure tempfile handling

References

Affected products

atop
  • ==through 1.26

Matching in nixpkgs

pkgs.numatop

Tool for runtime memory locality characterization and analysis of processes and threads on a NUMA system

Package maintainers

created 1 month ago
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable …

The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

References

Affected products

rails
  • ==2.3

Matching in nixpkgs

Package maintainers

created 1 month ago
Freeciv before 2.3.3 allows remote attackers to cause a denial …

Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.

Affected products

freeciv
  • ==before 2.3.3

Matching in nixpkgs

Package maintainers

created 1 month ago
A cross-site request forgery (CSRF) vulnerability in the Activity module …

A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

Affected products

Activity
  • ==6.x-1.x

Matching in nixpkgs

pkgs.gnomeExtensions.activitywatch-status

Shows the total time spent on the computer, fork of [activitywatch-status-gnome-shell](https://codeberg.org/cweiske/activitywatch-status-gnome-shell/)

  • nixos-unstable 2
    • nixpkgs-unstable 2
    • nixos-unstable-small 2
  • nixos-25.11 2
    • nixos-25.11-small 2
    • nixpkgs-25.11-darwin 2

pkgs.gnomeExtensions.activity-app-launcher

Integrates a category-based application launcher in the activities window. IMPORTANT: it needs the 'gnome-menus' and 'libgnome-menu-3-dev'; they must be installed in the system before installing this extension.

  • nixos-unstable 47
    • nixpkgs-unstable 47
    • nixos-unstable-small 47
  • nixos-25.11 45
    • nixos-25.11-small 45
    • nixpkgs-25.11-darwin 45
created 1 month ago
A double-free vulnerability exists in WebKit in Google Chrome before …

A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.

Affected products

Chrome
  • ==before Blink M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor …

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

References

Affected products

vsftpd
  • ==2.3.4 downloaded between 20110630 and 20110703

Matching in nixpkgs

Package maintainers

created 1 month ago
OpenTTD before 1.1.5 contains a Denial of Service (slow read …

OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.

References

Affected products

openttd
  • ==1.1.5

Matching in nixpkgs

pkgs.openttd

Open source clone of the Microprose game "Transport Tycoon Deluxe"

pkgs.openttd-ttf

TrueType typefaces for text in a pixel art style, designed for use in OpenTTD

Package maintainers