Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: python312Packages.waterfurnace

Found 3 matching suggestions

View:
Compact
Detailed
Untriaged
created 3 weeks ago
Out-of-bounds Read Overflow in tildearrow/furnace

Out-of-bounds Read vulnerability in tildearrow furnace (‎extern/libsndfile-modified/src modules). This vulnerability is associated with program files flac.C‎. This issue affects furnace: before 0.7.

Affected products

furnace
  • <0.7

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months, 2 weeks ago
A heap-based buffer over-read or buffer overflow in tildearrow/furnace

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules). This vulnerability is associated with program files inflate.C.

Affected products

furnace
  • <0.6.8.3

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2025-67528
5.1 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 2 months, 3 weeks ago
WordPress Urna theme <= 2.5.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.12.

Affected products

urna
  • =<<= 2.5.12

Matching in nixpkgs

pkgs.xournalpp

Xournal++ is a handwriting Notetaking software with PDF annotation support

pkgs.lazyjournal

TUI for journalctl, file system logs, as well as Docker and Podman containers

pkgs.qjournalctl

Qt-based graphical user interface for systemd's journalctl command

pkgs.journalwatch

Tool to find error messages in the systemd journal

pkgs.annapurna-sil

Unicode-based font family with broad support for writing systems that use the Devanagari script

Package maintainers