⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

Create Draft to queue a suggestion for refinement.

Dismiss to remove a suggestion from the queue.

CVE-2024-12840
5.0 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 10 months ago
Http proxies: satellite: service side request forgery in http proxies

A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can fetch the localhost banner.

security

pkgs.libmodsecurity

ModSecurity v3 library component.

pkgs.xml-security-c

C++ Implementation of W3C security standards for XML

pkgs.modsecurity-crs

The OWASP ModSecurity Core Rule Set is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls.

pkgs.modsecurity_standalone

Open source, cross-platform web application firewall (WAF)

pkgs.libmodsecurity.x86_64-linux

ModSecurity v3 library component.

pkgs.libmodsecurity.aarch64-linux

ModSecurity v3 library component.

pkgs.libmodsecurity.x86_64-darwin

ModSecurity v3 library component.

pkgs.libmodsecurity.aarch64-darwin

ModSecurity v3 library component.

pkgs.haskellPackages.hackage-security

Hackage security library

pkgs.python311Packages.flask-security

Quickly add security features to your Flask application

pkgs.python312Packages.flask-security

Quickly add security features to your Flask application

pkgs.python311Packages.securityreporter

Python wrapper for the Reporter API

pkgs.python312Packages.securityreporter

Python wrapper for the Reporter API

pkgs.haskellPackages.amazonka-securityhub

Amazon SecurityHub SDK

pkgs.haskellPackages.amazonka-securitylake

Amazon Security Lake SDK

pkgs.haskellPackages.hackage-security-HTTP

Hackage security bindings against the HTTP library

pkgs.python311Packages.azure-mgmt-security

Microsoft Azure Security Center Management Client Library for Python

pkgs.python312Packages.azure-mgmt-security

Microsoft Azure Security Center Management Client Library for Python

pkgs.pantheon.switchboard-plug-security-privacy

Switchboard Security & Privacy Plug

pkgs.haskellPackages.hackage-security.x86_64-linux

Hackage security library

pkgs.python311Packages.google-cloud-securitycenter

Cloud Security Command Center API API client library

pkgs.python312Packages.flask-security.x86_64-linux

Quickly add security features to your Flask application

pkgs.python312Packages.google-cloud-securitycenter

Cloud Security Command Center API API client library

pkgs.azure-cli-extensions.hardware-security-modules

Microsoft Azure Command-Line Tools AzureDedicatedHSMResourceProvider Extension

pkgs.haskellPackages.hackage-security.aarch64-linux

Hackage security library

pkgs.haskellPackages.hackage-security.x86_64-darwin

Hackage security library

pkgs.python312Packages.flask-security.aarch64-linux

Quickly add security features to your Flask application

pkgs.python312Packages.flask-security.x86_64-darwin

Quickly add security features to your Flask application

pkgs.haskellPackages.hackage-security.aarch64-darwin

Hackage security library

pkgs.python311Packages.types-aiobotocore-securityhub

Type annotations for aiobotocore securityhub

pkgs.python312Packages.flask-security.aarch64-darwin

Quickly add security features to your Flask application

pkgs.python312Packages.securityreporter.x86_64-linux

Python wrapper for the Reporter API

pkgs.python312Packages.types-aiobotocore-securityhub

Type annotations for aiobotocore securityhub

pkgs.python311Packages.types-aiobotocore-securitylake

Type annotations for aiobotocore securitylake

pkgs.python312Packages.securityreporter.aarch64-linux

Python wrapper for the Reporter API

pkgs.python312Packages.securityreporter.x86_64-darwin

Python wrapper for the Reporter API

pkgs.python312Packages.types-aiobotocore-securitylake

Type annotations for aiobotocore securitylake

pkgs.python311Packages.google-cloud-websecurityscanner

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.google-cloud-websecurityscanner

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.securityreporter.aarch64-darwin

Python wrapper for the Reporter API

pkgs.haskellPackages.hackage-security-HTTP.x86_64-linux

Hackage security bindings against the HTTP library

pkgs.haskellPackages.hackage-security-HTTP.aarch64-linux

Hackage security bindings against the HTTP library

pkgs.haskellPackages.hackage-security-HTTP.x86_64-darwin

Hackage security bindings against the HTTP library

pkgs.haskellPackages.hackage-security-HTTP.aarch64-darwin

Hackage security bindings against the HTTP library

pkgs.python311Packages.types-aiobotocore-codeguru-security

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.mypy-boto3-securityhub.x86_64-linux

Type annotations for boto3 securityhub

pkgs.python312Packages.types-aiobotocore-codeguru-security

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.mypy-boto3-securityhub.aarch64-linux

Type annotations for boto3 securityhub

pkgs.python312Packages.mypy-boto3-securityhub.x86_64-darwin

Type annotations for boto3 securityhub

pkgs.python312Packages.mypy-boto3-securitylake.x86_64-linux

Type annotations for boto3 securitylake

pkgs.python312Packages.mypy-boto3-securityhub.aarch64-darwin

Type annotations for boto3 securityhub

pkgs.python312Packages.mypy-boto3-securitylake.aarch64-linux

Type annotations for boto3 securitylake

pkgs.python312Packages.mypy-boto3-securitylake.x86_64-darwin

Type annotations for boto3 securitylake

pkgs.python312Packages.mypy-boto3-securitylake.aarch64-darwin

Type annotations for boto3 securitylake

pkgs.gnomeExtensions.arch-linux-updates-and-security-indicator

Update indicator for Arch Linux and GNOME Shell.
  • nixos-unstable 2
    • nixos-unstable-small 2
    • nixpkgs-unstable 2

pkgs.python312Packages.google-cloud-securitycenter.x86_64-linux

Cloud Security Command Center API API client library

pkgs.python312Packages.google-cloud-securitycenter.aarch64-linux

Cloud Security Command Center API API client library

pkgs.python312Packages.google-cloud-securitycenter.x86_64-darwin

Cloud Security Command Center API API client library

pkgs.python311Packages.microsoft-security-utilities-secret-masker

A tool for detecting and masking secrets

pkgs.python312Packages.google-cloud-securitycenter.aarch64-darwin

Cloud Security Command Center API API client library

pkgs.python312Packages.microsoft-security-utilities-secret-masker

A tool for detecting and masking secrets

pkgs.python312Packages.types-aiobotocore-securityhub.x86_64-linux

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securityhub.aarch64-linux

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securityhub.x86_64-darwin

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securitylake.x86_64-linux

Type annotations for aiobotocore securitylake

pkgs.python312Packages.google-cloud-websecurityscanner.x86_64-linux

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.types-aiobotocore-securityhub.aarch64-darwin

Type annotations for aiobotocore securityhub

pkgs.python312Packages.types-aiobotocore-securitylake.aarch64-linux

Type annotations for aiobotocore securitylake

pkgs.python312Packages.types-aiobotocore-securitylake.x86_64-darwin

Type annotations for aiobotocore securitylake

pkgs.python312Packages.google-cloud-websecurityscanner.aarch64-linux

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.google-cloud-websecurityscanner.x86_64-darwin

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.types-aiobotocore-securitylake.aarch64-darwin

Type annotations for aiobotocore securitylake

pkgs.python312Packages.google-cloud-websecurityscanner.aarch64-darwin

Google Cloud Web Security Scanner API client library

pkgs.python312Packages.types-aiobotocore-codeguru-security.x86_64-linux

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.types-aiobotocore-codeguru-security.aarch64-linux

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.types-aiobotocore-codeguru-security.x86_64-darwin

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.types-aiobotocore-codeguru-security.aarch64-darwin

Type annotations for aiobotocore codeguru-security

pkgs.python312Packages.microsoft-security-utilities-secret-masker.x86_64-linux

A tool for detecting and masking secrets

pkgs.python312Packages.microsoft-security-utilities-secret-masker.aarch64-linux

A tool for detecting and masking secrets

pkgs.python312Packages.microsoft-security-utilities-secret-masker.x86_64-darwin

A tool for detecting and masking secrets

pkgs.python312Packages.microsoft-security-utilities-secret-masker.aarch64-darwin

A tool for detecting and masking secrets
Package maintainers: 12
CVE-2024-1132
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 10 months ago
Keycloak: path transversal in redirection validation

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

keycloak
<24.0.3
<22.0.10
keycloak-core
rh-sso7-keycloak
*
rhbk/keycloak-rhel9
*
mtr/mtr-rhel8-operator
*
mtr/mtr-operator-bundle
*
mta/mta-windup-addon-rhel9
*
org.keycloak/keycloak-core
mtr/mtr-web-container-rhel8
*
org.keycloak-keycloak-parent
rhbk/keycloak-rhel9-operator
*
rhbk/keycloak-operator-bundle
*
rh-sso-7/sso76-openshift-rhel8
*
mtr/mtr-web-executor-container-rhel8
*
org.wildfly.security-wildfly-elytron-parent

pkgs.keycloak

Identity and access management for modern applications and services

pkgs.terraform-providers.keycloak

pkgs.python311Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2024-37962
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 10 months ago
WordPress Fusion Page Builder plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Fusion allows Stored XSS.This issue affects Fusion: from n/a through 1.6.1.

fusion
=<1.6.1

pkgs.datafusion-cli

cli for Apache Arrow DataFusion

pkgs.lxgw-fusionkai

Simplified Chinese font derived from LXGW WenKai GB, iansui and Klee One

pkgs.finalfusion-utils

Utility for converting, quantizing, and querying word embeddings

pkgs.python311Packages.datafusion

Extensible query execution framework

pkgs.python312Packages.datafusion

Extensible query execution framework

pkgs.haskellPackages.fusion-plugin

GHC plugin to make stream fusion more predictable

pkgs.python311Packages.finalfusion

Python module for using finalfusion, word2vec, and fastText word embeddings

pkgs.python312Packages.finalfusion

Python module for using finalfusion, word2vec, and fastText word embeddings

pkgs.haskellPackages.fusion-plugin-types

Types for the fusion-plugin package

pkgs.vimPlugins.nvim-treesitter-parsers.fusion

  • nixos-unstable ???
    • nixos-unstable-small
    • nixpkgs-unstable

pkgs.haskellPackages.fusion-plugin.x86_64-linux

GHC plugin to make stream fusion more predictable

pkgs.python312Packages.k-diffusion.x86_64-linux

Karras et al. (2022) diffusion models for PyTorch

pkgs.haskellPackages.fusion-plugin.aarch64-linux

GHC plugin to make stream fusion more predictable

pkgs.haskellPackages.fusion-plugin.x86_64-darwin

GHC plugin to make stream fusion more predictable

pkgs.python312Packages.k-diffusion.aarch64-linux

Karras et al. (2022) diffusion models for PyTorch

pkgs.python312Packages.k-diffusion.x86_64-darwin

Karras et al. (2022) diffusion models for PyTorch

pkgs.haskellPackages.fusion-plugin.aarch64-darwin

GHC plugin to make stream fusion more predictable

pkgs.haskellPackages.fusion-plugin-types.x86_64-linux

Types for the fusion-plugin package

pkgs.haskellPackages.fusion-plugin-types.aarch64-linux

Types for the fusion-plugin package

pkgs.haskellPackages.fusion-plugin-types.x86_64-darwin

Types for the fusion-plugin package

pkgs.haskellPackages.fusion-plugin-types.aarch64-darwin

Types for the fusion-plugin package
Package maintainers: 4
CVE-2024-11614 created 10 months, 1 week ago
Dpdk: denial of service from malicious guest on hypervisors using dpdk vhost library

An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.

dpdk
*
<21.11-4
openvswitch
openvswitch3.0
openvswitch3.1
*
openvswitch3.2
openvswitch3.3
*
openvswitch3.4
*
openvswitch2.10
openvswitch2.11
openvswitch2.12
openvswitch2.13
openvswitch2.15
openvswitch2.16
openvswitch2.17

pkgs.dpdk

Set of libraries and drivers for fast packet processing

pkgs.openvswitch

Multilayer virtual switch

pkgs.openvswitch-dpdk

Multilayer virtual switch

pkgs.linuxPackages_zen.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_6_1.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages_zen.dpdk.x86_64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_5_10.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages_zen.dpdk.aarch64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_libre.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_zen.odp-dpdk.x86_64-linux

Open Data Plane optimized for DPDK

pkgs.linuxPackages_zen.odp-dpdk.aarch64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_libre.odp-dpdk

Open Data Plane optimized for DPDK

pkgs.linuxPackages_lqx.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_zen.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_libre.dpdk-kmods

Kernel modules for DPDK

pkgs.linuxPackages-libre.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages-libre.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_xanmod.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_4_hardened.odp-dpdk

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_5_10.dpdk.x86_64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_5_10.dpdk.aarch64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxPackages_6_1_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest-libre.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_10_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_15_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_6_11_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_6_1_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_latest-libre.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_xanmod_stable.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_10_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_5_15_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxPackages_6_11_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10.odp-dpdk.x86_64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_5_10.odp-dpdk.aarch64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_5_4.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_1.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_6.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_4.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_1.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_12.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_6.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_12.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk.x86_64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_latest_libre.dpdk.aarch64-linux

Set of libraries and drivers for fast packet processing

pkgs.linuxKernel.packages.linux_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.odp-dpdk.x86_64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.odp-dpdk.aarch64-linux

Open Data Plane optimized for DPDK

pkgs.linuxKernel.packages.linux_6_1_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11_hardened.dpdk-kmods.x86_64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_1_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_latest_libre.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_10_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_5_15_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK

pkgs.linuxKernel.packages.linux_6_11_hardened.dpdk-kmods.aarch64-linux

Kernel modules for DPDK
Package maintainers: 9
CVE-2023-52355
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 10 months, 1 week ago
Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

iv
tkimg
libtiff
<4.6.0
mingw-libtiff
compat-libtiff3

pkgs.libtiff

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-darwin

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-darwin

Library and utilities for working with the TIFF image file format
Package maintainers: 7
CVE-2023-6228
3.3 LOW
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 10 months, 1 week ago
Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c

An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.

tkimg
libtiff
*
mingw-libtiff
compat-libtiff3

pkgs.libtiff

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-linux

Library and utilities for working with the TIFF image file format

pkgs.libtiff.x86_64-darwin

Library and utilities for working with the TIFF image file format

pkgs.libtiff.aarch64-darwin

Library and utilities for working with the TIFF image file format
Package maintainers: 7
CVE-2024-54350
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
created 10 months, 1 week ago
WordPress hmd theme <= 2.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

hmd
=<2.0

pkgs.openhmd

Library API and drivers immersive technology
Package maintainers: 1
CVE-2024-10973
5.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): ADJACENT_NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 10 months, 1 week ago
Keycloak: cli option for encrypted jgroups ignored

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.

keycloak
*
<23.0
<25.0
org.keycloak/keycloak-quarkus-server

pkgs.keycloak

Identity and access management for modern applications and services

pkgs.terraform-providers.keycloak

pkgs.python311Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-linux

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.x86_64-darwin

Provides access to the Keycloak API

pkgs.python312Packages.python-keycloak.aarch64-darwin

Provides access to the Keycloak API
Package maintainers: 3
CVE-2024-0874
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 10 months, 1 week ago
Coredns: cd bit response is cached and served later

A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.

coredns
<1.11.2
openshift4/ose-coredns
*
openshift4/ose-coredns-rhel9
*
rhacm2/lighthouse-agent-rhel8
rhacm2/lighthouse-agent-rhel9
openshift-logging/logging-loki-rhel8
openshift-logging/logging-loki-rhel9
rhacm2-tech-preview/lighthouse-agent-rhel8

pkgs.coredns

DNS server that runs middleware
Package maintainers: 3
CVE-2024-54384
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 10 months, 1 week ago
WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.8.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in eLightUp Falcon – WordPress Optimizations & Tweaks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through 2.8.3.

falcon
=<2.8.3

pkgs.python311Packages.falcon

Unladen web framework for building APIs and app backends

pkgs.python312Packages.falcon

Unladen web framework for building APIs and app backends
Package maintainers: 2