Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month ago
Thunar before 1.3.1 could crash when copy and pasting a …

Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.

References

Affected products

thunar
  • ==before 1.3.1

Matching in nixpkgs

Package maintainers

created 1 month ago
Moodle before 2.2.2 has Personal information disclosure, when administrative setting …

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.

References

Affected products

Moodle
  • ==2.0 to 2.0.7+
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Package maintainers

created 1 month ago
A memory leak in rsyslog before 5.7.6 was found in …

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.

References

Affected products

rsyslog
  • ==before 5.7.6

Matching in nixpkgs

created 1 month ago
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

Affected products

Gallery
  • ==1.4

Matching in nixpkgs

created 1 month ago
poppler before 0.16.3 has malformed commands that may cause corruption …

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

Affected products

poppler
  • ==before 0.16.3

Matching in nixpkgs

Package maintainers

created 1 month ago
offlineimap before 6.3.4 added support for SSL server certificate validation …

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

References

Affected products

offlineimap
  • ==before 6.3.4

Matching in nixpkgs

pkgs.offlineimap

Synchronize emails between two repositories, so that you can read the same mailbox from multiple computers

created 1 month ago
A memory leak in rsyslog before 5.7.6 was found in …

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset

References

Affected products

rsyslog
  • ==before 5.7.6

Matching in nixpkgs

created 1 month ago
Moodle before 2.2.2 has a permission issue in Forum Subscriptions …

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

References

Affected products

Moodle
  • ==2.2 to 2.2.1+
  • ==2.1 to 2.1.4+

Matching in nixpkgs

Package maintainers

created 1 month ago
Bad cast in CSS in Google Chrome prior to 11.0.0.0 …

Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

References

Affected products

Chrome
  • <11.0.0.0

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
The $smarty.template variable in Smarty3 allows attackers to possibly execute …

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.

Affected products

smarty3
  • ==3

Matching in nixpkgs

Package maintainers