| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_6 22 Oct 2025 16:18:13
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 21 Oct 2025 16:57:56
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 141.0.7390.107
Obtained
from: https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_14.html
Obtained
from: https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop.html |
1.1_6 21 Oct 2025 13:45:49
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb[78] vulnerability
* CVE-2025-11979 |
1.1_6 20 Oct 2025 20:23:19
    |
Dan Langille (dvl)  |
security/vuxml: Add entry for net-mgmt/icingaweb2-module-icingadb
* CVE-2025-61789 |
1.1_6 19 Oct 2025 16:22:28
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add more Mozilla vulnerabilities
* CVE-2025-11712
* CVE-2025-11711
* CVE-2025-11710
* CVE-2025-11709
* CVE-2025-11708
* CVE-2025-11714
While here improve another Mozilla entry description a bit. |
1.1_6 17 Oct 2025 17:55:04
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-11715
* CVE-2025-11721 |
1.1_6 17 Oct 2025 17:25:00
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Firefox vulnerability
* CVE-2025-11152 |
1.1_6 17 Oct 2025 17:21:57
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-10537
* CVE-2025-10536
* CVE-2025-10534
* CVE-2025-10533 |
1.1_6 17 Oct 2025 10:48:51
    |
Muhammad Moinur Rahman (bofh)  |
security/vuxml: Add report for minio |
1.1_6 13 Oct 2025 21:30:31
    |
Craig Leres (leres)  |
security/vuxml: Mark zeek < 8.0.2 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v8.0.2
This release fixes the following vulnerability:
- The KRB analyzer can leak information about hosts in analyzed
traffic via external DNS lookups.
Reported by: Tim Wojtulewicz |
1.1_6 13 Oct 2025 17:25:40
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Firefox vulnerability
* CVE-2025-11153 |
1.1_6 10 Oct 2025 08:51:17
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 09 Oct 2025 11:13:39
    |
Guido Falsi (madpilot)  |
security/vuxml: Report mailpit information disclosure vuln
Obtained from: https://github.com/axllent/mailpit/releases/tag/v1.27.10 |
1.1_6 07 Oct 2025 15:50:01
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities |
1.1_6 07 Oct 2025 06:21:45
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix mongodb entries
Remove entry that only affects 8.1.x which we don't still have in the repo.
Modify an entry removing the 8.1.x entry from the affected packages
Reported by: ronald-lists@klop.ws
Fixes: 7ec6fda16269 |
1.1_6 06 Oct 2025 16:34:20
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities |
1.1_6 06 Oct 2025 15:50:56
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Remove redundant version information |
1.1_6 06 Oct 2025 15:43:39
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb vulnerabilities
* CVE-2025-10061
* CVE-2025-10060
* CVE-2025-10059
* CVE-2025-7259 |
1.1_6 05 Oct 2025 17:27:00
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb6 vulnerability
* CVE-2024-8654 |
1.1_6 04 Oct 2025 12:00:53
    |
Muhammad Moinur Rahman (bofh)  |
security/vuxml: Add multiple CVEs for redis and valkey |
1.1_6 04 Oct 2025 09:34:35
    |
Matthias Andree (mandree)  |
security/vuxml: Add CVE-2025-61962 to fetchmail
add CVE-2025-61962 to existing fetchmail < 6.5.6 SMTP AUTH entry
Security: 21fba35e-a05f-11f0-a8b8-a1ef31191bc1
Security: CVE-2025-61962 |
1.1_6 04 Oct 2025 03:09:08
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt6-webengine < 6.9.3 |
1.1_6 03 Oct 2025 13:58:16
    |
Matthias Andree (mandree)  |
security/vuxml: Add mail/fetchmail < 6.5.6 vuln (SMTP AUTH)
CVE requested from MITRE but not received yet.
URL: https://www.fetchmail.info/fetchmail-SA-2025-01.txt
Security: 21fba35e-a05f-11f0-a8b8-a1ef31191bc1 |
1.1_6 03 Oct 2025 07:13:30
    |
Philip Paeps (philip)  |
security/vuxml: reference FreeBSD-SA-25:08.openssl
Add a reference to FreeBSD-SA-25:08.openssl (issued 2025-09-30) to the
vuxml entry for OpenSSL CVE-2025-9230, CVE-2025-9231 and CVE-2025-9232.
FreeBSD-SA-25:08.openssl affects all supported versions of FreeBSD |
1.1_6 03 Oct 2025 07:03:05
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 141.0.7390.54
Obtained
from: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_30.html |
1.1_6 02 Oct 2025 23:17:17
    |
Wen Heping (wen)  |
security/vuxml: Document Django's multiple vulnerabilities |
1.1_6 01 Oct 2025 18:48:27
    |
Bernard Spil (brnrd)  |
security/vuxml: Mark OpenSSL 3.6 and 3.3 QUICTLS vulnerable too |
1.1_6 01 Oct 2025 09:44:24
    |
Muhammad Moinur Rahman (bofh)  |
security/vuxml: Add entry for py-mysql-connector-python
PR: 289934
Reported by: patrik@hildingsson.se |
1.1_6 01 Oct 2025 06:52:15
    |
Bernard Spil (brnrd)  |
security/vuxml: Register OpenSSL vulnerabilities |
1.1_6 01 Oct 2025 06:43:48
    |
Bernard Spil (brnrd)  |
security/vuxml: Register LibreSSL vulnerability |
1.1_6 28 Sep 2025 16:16:39
    |
Fernando Apesteguía (fernape)  |
security/vuxml: krb5-1.20 is not vulnerable to CVE-2023-39975
PR: 274159
Reported by: wollman@FreeBSD.org |
1.1_6 28 Sep 2025 16:03:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: fix SQLite entry
Vulnerable version range for sqlite currently bundled in
linux_base-rl9 (CVE-2025-6595).
PR: 289358
Reported by: jcfyecrayz@liamekaens.com |
1.1_6 28 Sep 2025 15:55:04
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Record textproc/goldendict vulnerability |
1.1_6 26 Sep 2025 17:19:31
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix some reporters
Reported by: dan@langille.org |
1.1_6 26 Sep 2025 16:17:33
    |
Fernando Apesteguía (fernape)  Author: Pau Amma |
security/vuxml: record security fixes in sysutils/libudisks 2.10.{2,91}
PR: 289689
Reported by: pauamma@gundo.com |
1.1_6 26 Sep 2025 15:59:40
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry
"SO-AND-SO" is not a valid reporter.
Fixes: 21c77e23be74b |
1.1_6 26 Sep 2025 15:57:23
    |
Florian Smeets (flo)  Author: Ralf van der Enden |
security/vuxml: Document net/quiche vulnerabilities
PR: 289810 |
1.1_6 26 Sep 2025 15:30:04
    |
Florian Smeets (flo)  |
security/vuxml: Add 1.9.X branch of dnsdist to recent entry
PR: 289811 |
1.1_6 26 Sep 2025 06:37:21
    |
Matthias Fechner (mfechner)  |
security/vuxml: gitlab vulnerabilities |
1.1_6 25 Sep 2025 23:34:48
    |
Matthias Andree (mandree)  |
security/vuxml: add openvpn-devel < 2.7beta2 vuln
PR: 289838
Security: e5cf9f44-9a64-11f0-8241-93c889bb8de1
Security: CVE-2025-10680 |
1.1_6 24 Sep 2025 18:28:18
    |
Florian Smeets (flo)  Author: Ralf van der Enden |
security/vuxml: Add dns/dnsdist vulnerability < 2.0.1 |
1.1_6 23 Sep 2025 21:00:20
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 140.0.7339.207
Obtained
from: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_23.html |
1.1_6 22 Sep 2025 12:31:03
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 140.0.7339.185
Obtained
from: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html |
1.1_6 20 Sep 2025 08:08:22
    |
Daniel Engberg (diizzy)  |
security/vuxml: Add pcre2 vulnerability
Document CVE-2025-58050 |
1.1_6 18 Sep 2025 21:11:18
    |
Sergey A. Osokin (osa)  |
security/vuxml: update expat records
Reported by: delphij
Fixes: f0e1c34246486f53b0636ec39f73edb116a52f3f |
1.1_6 18 Sep 2025 21:05:59
    |
Sergey A. Osokin (osa)  |
security/vuxml: add expat2 vulnerability |
1.1_6 17 Sep 2025 18:38:44
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2025-09-17
Sponsored by: The FreeBSD Foundation |
1.1_6 16 Sep 2025 14:55:43
    |
Tijl Coosemans (tijl)  |
security/vuxml: Merge 2 entries for CUPS
Reported by: osa |
1.1_6 16 Sep 2025 07:24:15
    |
Tijl Coosemans (tijl)  |
security/vuxml: Document CUPS vulnerabilities
CVE-2025-58060 cups: Authentication bypass with AuthType Negotiate
CVE-2025-58364 cups: Remote DoS via null dereference |
1.1_6 14 Sep 2025 18:29:31
    |
Sergey A. Osokin (osa)  |
security/vuxml: correct the product version with a security fix |
1.1_6 14 Sep 2025 17:39:16
    |
Sergey A. Osokin (osa)  |
security/vuxml: add www/unit-java vulnerability |
1.1_6 13 Sep 2025 21:59:21
    |
Sergey A. Osokin (osa)  |
security/vuxml: update cups vulnerabilities |
1.1_6 12 Sep 2025 16:42:10
    |
Sergey A. Osokin (osa)  |
security/vuxml: add print/cups < 2.4.13 |
1.1_6 11 Sep 2025 08:27:28
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 140.0.7339.127
Obtained
from: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html |
1.1_6 11 Sep 2025 05:20:29
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 07 Sep 2025 09:51:29
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 140.0.7339.80
Obtained
from: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.html |
1.1_6 05 Sep 2025 14:46:52
    |
Sergey A. Osokin (osa)  |
security/vuxml: adjust libxslt version
Please visit https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289213
for details. |
1.1_6 04 Sep 2025 07:12:01
    |
Jason E. Hale (jhale)  |
security/vuxml: Add graphics/exiv2 < 0.28.6 |
1.1_6 04 Sep 2025 02:47:26
    |
Wen Heping (wen)  |
security/vuxml: Document Django's multiple vulnerabilities |
1.1_6 03 Sep 2025 19:29:53
    |
Palle Girgensohn (girgen)  |
security/vuxml: document shibboleth vulnerability |
1.1_6 03 Sep 2025 15:38:54
    |
Nicola Vitale (nivit)  |
security/vuxml: Add www/linux-vieb < 12.4.0 |
1.1_6 29 Aug 2025 03:22:52
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 28 Aug 2025 19:42:05
    |
Renato Botelho (garga)  |
security/vuxml: Adjust affected kea versions
CVE-2025-40779 doesn't affect Kea 2.6.x, which is the version present on
quarterly branch. On net/kea, it only affects 3.0.0 while it affects
3.1.0 and 2.7.x on net/kea-devel. |
1.1_6 28 Aug 2025 19:32:40
    |
Renato Botelho (garga)  Author: Andrey Pevnev |
security/vuxml: Add net/kea vulnerability
* CVE-2025-40779 |
1.1_6 28 Aug 2025 05:06:27
    |
Jason E. Hale (jhale)  |
security/vuxml: Add devel/qt6-base < 6.9.2 |
1.1_6 28 Aug 2025 05:06:26
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt6-webengine < 6.9.2 |
1.1_6 27 Aug 2025 17:02:53
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry
Fixes: 35f7214f7a9ec |
1.1_6 27 Aug 2025 17:00:06
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add SQLite vulnerability
* CVE-2025-29088 |
1.1_6 24 Aug 2025 11:42:50
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add p5-Catalyst-Authentication-Credential-HTTP |
1.1_6 22 Aug 2025 15:28:41
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-9187
* CVE-2025-9184
* CVE-2025-9185
* CVE-2025-9183
* CVE-2025-9182
* CVE-2025-9181
* CVE-2025-9180
* CVE-2025-9179 |
1.1_6 15 Aug 2025 16:10:38
    |
Sergey A. Osokin (osa)  |
security/vuxml: add www/nginx-devel < 1.29.1
Obtained from: https://my.f5.com/manage/s/article/K000152786 |
1.1_6 14 Aug 2025 19:16:40
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 139.0.7258.127
Obtained
from: https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html |
1.1_6 14 Aug 2025 14:10:16
    |
Palle Girgensohn (girgen)  |
security/vuxml: Add vulnerabilities for PostgreSQL |
1.1_6 14 Aug 2025 03:41:47
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 13 Aug 2025 15:41:08
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document www/varnish7 DoS condition |
1.1_6 13 Aug 2025 09:19:28
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: add security/p5-Authen-SASL |
1.1_6 11 Aug 2025 08:10:50
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 139.0.7258.66
Obtained
from: https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop.html |
1.1_6 09 Aug 2025 14:19:07
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache httpd vulnerability |
1.1_6 08 Aug 2025 01:20:58
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA issued on 2025-08-08
FreeBSD-SA-25:07.libarchive affects all supported versions of FreeBSD. |
1.1_6 02 Aug 2025 16:57:24
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Sqlite vulnerability
* CVE-2025-3277 |
1.1_6 01 Aug 2025 09:51:05
    |
Matthias Andree (mandree)  |
security/vuxml: navidrome < 0.56.0 CVE-2025-48948
This wasn't mentioned along with the other navidrome < 0.56
vuln and also has a wider affected version range.
Security: CVE-2025-48948
Security: 95480188-6ebc-11f0-8a78-bf201f293bce |
1.1_6 01 Aug 2025 09:45:34
    |
Matthias Andree (mandree)  |
security/vuxml: fixup linux_base -> linux_base-rl9 |
1.1_6 01 Aug 2025 09:41:36
    |
Matthias Andree (mandree)  |
security/vuxml: clean up sqlite3 version range mess
Several sqlite3 entries mentioned wrong version ranges
with respect to PORTEPOCH and/or forgot the linux-*-sqlite
or, more recently, linux_base port.
While auditing this, I saw several implausible tags that used <gt>
(greater-than) in ranges where I believe that <ge> (greater-or-equal)
would be more adequate.
Add relevant reminders to vuxml's Makefile.
Fix up sqlite3's 2025 entries.
linux_base-rl9 currently ships 3.34.1-7.el9_3, see
emulators/linux_base-rl9/Makefile.version - I don't know if that's
vulnerable or was patched inside Rocky Linux, but let's err on the safe side.
I'll leave it up to emulation@ to clean up this particular entry. |
1.1_6 01 Aug 2025 08:52:38
    |
Matthias Andree (mandree)  |
security/vuxml: fix up range for sqlite3's CVE-2025-7458
Security: f51077bd-6dd7-11f0-9d62-b42e991fc52e
Security: CVE-2025-7458 |
1.1_6 31 Jul 2025 06:40:27
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Sqlite vulnerability
CVE_ID=CVE-2025-7458 |
1.1_6 29 Jul 2025 20:22:43
    |
Rodrigo Osorio (rodrigo)  |
security/vuxml: Use of Cryptographically Weak Pseudo-Random Number Generator in
p5-Crypt-CBC
Also, fix typo missing space in previous report. |
1.1_6 27 Jul 2025 12:31:03
    |
Dan Langille (dvl)  |
security/vuxml: Add devel/viewvc-devel entry |
1.1_6 25 Jul 2025 21:59:11
    |
Yasuhiro Kimura (yasu)  |
security/vuxml: Document possible DoS valnerability in rubygem-resolv |
1.1_6 24 Jul 2025 16:09:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-8027
* CVE-2025-8028
* CVE-2025-8029
* CVE-2025-8030
* CVE-2025-8031
* CVE-2025-8032
* CVE-2025-8033
* CVE-2025-8034
* CVE-2025-8035
* CVE-2025-8036
* CVE-2025-8037
* CVE-2025-8038
* CVE-2025-8039
* CVE-2025-8040
* CVE-2025-8043
* CVE-2025-8044 |
1.1_6 24 Jul 2025 16:04:14
    |
Sergey A. Osokin (osa)  |
security/vuxml: document gdk-pixbuf2 vulnerability |
1.1_6 24 Jul 2025 13:08:36
    |
Hiroki Tagato (tagattie)  Author: Ralf van der Enden |
security/vuxml: add dns/powerdns-recursor entry for CVE-2025-30192
PR: 288384
Reported by: Ralf van der Enden <tremere@cainites.net>
Obtained from: https://blog.powerdns.com/powerdns-security-advisory-2025-04 |
1.1_6 24 Jul 2025 03:27:52
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 23 Jul 2025 19:29:20
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add sqlite3 vulnerability
CVE-2025-6965 |
1.1_6 22 Jul 2025 18:33:02
    |
Max Brazhnikov (makc)  |
security/vuxml: Document 7-zip vulnerability
Prompted by: asomers@ |
1.1_6 21 Jul 2025 20:44:53
    |
Daniel Engberg (diizzy)  |
security/vuxml: Adjust affected versions for openh264 (CVE-2025-27091)
Adjust range to since port uses PORTEPOCH
Fixes: 13dd451 |
1.1_6 20 Jul 2025 04:32:53
    |
Sergey A. Osokin (osa)  |
security/vuxml: document libwasmtime vulnerability |
1.1_6 18 Jul 2025 21:03:08
    |
Hiroki Tagato (tagattie)  Author: Jaap Akkerhuis |
security/vuxml: document unbound cache poisoning via the ECS-enabled rebirthday
attack
PR: 288276
Reported by: Jaap Akkerhuis <jaap@NLnetLabs.nl> |
1.1_6 16 Jul 2025 20:06:13
    |
Michael Osipov (michaelo)  |
security/vuxml: Fix ranges for Tomcat vulnerabilities
Approved by: otis (mentor), jbeich, vvd (maintainer)
Differential Revision: https://reviews.freebsd.org/D51323 |
1.1_6 15 Jul 2025 18:37:23
    |
Matthias Andree (mandree)  |
security/vuxml: libxml2 fixed version is 2.14.5.
Security: abbc8912-5efa-11f0-ae84-99047d0a6bcc |
1.1_6 14 Jul 2025 18:44:35
    |
Bernard Spil (brnrd)  |
security/vuxml: Document liboqs vulnerability |