Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing …

Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.

References

Affected products

Calibre
  • ==unknown

Matching in nixpkgs

pkgs.calibre-web

Web app for browsing, reading and downloading eBooks stored in a Calibre database

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Moodle before 2.2.2 has Personal information disclosure, when administrative setting …

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+
  • ==2.0 to 2.0.7+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Package maintainers

created 2 months ago Activity log
  • Created suggestion
In xpdf, the xref table contains an infinite loop which …

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.

Affected products

poppler
  • ==0.26.5-2

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Moodle before 2.2.2 has a password and web services issue …

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+
  • ==2.0 to 2.0.7+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Package maintainers

created 2 months ago Activity log
  • Created suggestion
PackageKit 0.6.17 allows installation of unsigned RPM packages as though …

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.

References

Affected products

packagekit
  • ==0.6.17
  • ==0.6.15

Matching in nixpkgs

pkgs.packagekit

System to facilitate installing and updating packages

pkgs.gnome-packagekit

Tools for installing software on the GNOME desktop using PackageKit

  • nixos-unstable 43.0
    • nixpkgs-unstable 43.0
    • nixos-unstable-small 43.0
  • nixos-25.11 43.0
    • nixos-25.11-small 43.0
    • nixpkgs-25.11-darwin 43.0

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers …

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

Affected products

tahoe-lafs
  • ==1.10.0-2

Matching in nixpkgs

Package maintainers

Permalink CVE-2010-0048
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 2 months ago Activity log
  • Created suggestion
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows …

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.

References

Affected products

n/a
  • ==n/a
safari
  • ==4.0.3
  • ==4.0
  • ==4.0.2
  • ==4.0.1
  • =<4.0.4

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
An unchecked sscanf() call in ettercap before 0.7.5 allows an …

An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.

Affected products

ettercap
  • ==0.7.3

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
gpw generates shorter passwords than required

gpw generates shorter passwords than required

Affected products

gpw
  • ==0.0.19940601-8.1

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
rpcbind 0.2.0 allows local users to write to arbitrary files …

rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.

Affected products

rpcbind
  • ==0.2.0

Matching in nixpkgs

Package maintainers