Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month, 1 week ago
An issue exists in WebKit in Google Chrome before Blink …

An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.

Affected products

Chrome
  • ==before Blink M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month, 1 week ago
xpdf allows remote attackers to cause a denial of service …

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

Affected products

xpdf
  • ==N/A

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race …

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

References

Affected products

libuser
  • ==0.56
  • ==0.57

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
plow has local buffer overflow vulnerability

plow has local buffer overflow vulnerability

Affected products

plow
  • ==0.0.1
  • ==0.0.2

Matching in nixpkgs

pkgs.plow

High-performance HTTP benchmarking tool that includes a real-time web UI and terminal display

Package maintainers

created 1 month, 1 week ago
A cross-site scripting vulnerability flaw was found in the auto_link …

A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

Affected products

rails
  • ==rails 3.0.6

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
It was found that various OpenID Providers (OPs) had TLS …

It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.

Affected products

openid
  • ==unknown

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in …

OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

References

Affected products

OverlayFS
  • ==as used in Ubuntu 10.0.4 LTS and 11.10
  • ==before 3.0.0-16.28

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
Missing verification of host key for kdump server

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).

Affected products

kdump
  • <2012-01-20

Matching in nixpkgs

Package maintainers

Permalink CVE-2010-0048
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 1 week ago
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows …

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.

References

Affected products

n/a
  • ==n/a
safari
  • ==4.0.2
  • =<4.0.4
  • ==4.0.3
  • ==4.0.1
  • ==4.0

Matching in nixpkgs

created 1 month, 1 week ago
Mozilla Firefox before 3.6 is vulnerable to XSS via the …

Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets

References

Affected products

Firefox
  • ==before 3.6

Matching in nixpkgs

Package maintainers