non port: security/vuxml/vuln.xml |
Number of commits found: 6273 (showing only 100 on this page) |
Thursday, 24 Dec 2015
|
17:09 miwi
- Adjust latest py*-django entry
Discussed with: feld
 |
14:57 junovitch
Document information disclosure vulnerability in the Mantis Bug Tracker
PR: 201106
Security: CVE-2015-5059
Security: https://vuxml.FreeBSD.org/freebsd/e1b5318c-aa4d-11e5-8f5c-002590263bf5.html
 |
14:08 junovitch
Update earlier MediaWiki entry (r394240) with CVE assignment information
PR: 202328
Security: CVE-2013-7444
Security: CVE-2015-6727
Security: CVE-2015-6728
Security: CVE-2015-6729
Security: CVE-2015-6730
Security: CVE-2015-6731
Security: CVE-2015-6733
Security: CVE-2015-6734
Security: CVE-2015-6735
Security: CVE-2015-6736
Security: CVE-2015-6737
Security:
https://vuxml.FreeBSD.org/freebsd/6241b5df-42a1-11e5-93ad-002590263bf5.html
 |
14:02 junovitch
Update earlier MediaWiki entry (r400007) with CVE assignment information
Security: CVE-2015-8001
Security: CVE-2015-8002
Security: CVE-2015-8003
Security: CVE-2015-8004
Security: CVE-2015-8005
Security: CVE-2015-8006
Security: CVE-2015-8007
Security: CVE-2015-8008
Security: CVE-2015-8009
Security: https://vuxml.FreeBSD.org/freebsd/b973a763-7936-11e5-a2a1-002590263bf5.html
 |
13:54 junovitch
Document recent MediaWiki vulnerabilities
Security: CVE-2015-8628
Security: CVE-2015-8627
Security: CVE-2015-8626
Security: CVE-2015-8625
Security: CVE-2015-8624
Security: CVE-2015-8623
Security: CVE-2015-8622
Security: https://vuxml.FreeBSD.org/freebsd/f36bbd66-aa44-11e5-8f5c-002590263bf5.html
 |
13:17 sunpoet
- Fix r404311: incomplete version range leads to false positive
 |
Wednesday, 23 Dec 2015
|
19:07 sunpoet
- Document Ruby vulnerability
 |
11:14 ohauer
- document Bugzilla security issues
 |
Tuesday, 22 Dec 2015
|
01:43 junovitch
Document two librsvg2 vulnerabilities
PR: 205502
Security: CVE-2015-7557
Security: CVE-2015-7558
Security: https://vuxml.FreeBSD.org/freebsd/da634091-a84a-11e5-8f5c-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/d6c51737-a84b-11e5-8f5c-002590263bf5.html
 |
Monday, 21 Dec 2015
|
15:39 feld
irc/quassel: Document vulnerability
Security: CVE-2015-8547
 |
00:41 junovitch
Revise Moodle multiple security vulnerabilities from r401745 to reflect
recently published advisory
Security: https://vuxml.FreeBSD.org/freebsd/82b3ca2a-8c07-11e5-bd18-002590263bf5.html
 |
Sunday, 20 Dec 2015
|
23:44 novel
Document libvirt vulnerability
Security: CVE-2015-5313
 |
Saturday, 19 Dec 2015
|
23:42 timur
Add entry for multiple Samba vulnerabilities
 |
Friday, 18 Dec 2015
|
19:54 rene
Document new vulnerabilities in www/chromium < 47.0.2526.106
Obtained
from: http://googlechromereleases.blogspot.nl/2015/12/stable-channel-update_15.html
 |
01:34 junovitch
Add PHP 5.6 package name to an earlier PHP VuXML entry
PR: 200779
Security: CVE-2015-5590
Security: CVE-2015-5589
Security: https://vuxml.FreeBSD.org/freebsd/8b1f53f3-2da5-11e5-86ff-14dae9d210b8.html
 |
Thursday, 17 Dec 2015
|
18:14 feld
Document vulns in cups-filters and foomatic-filters
Security: CVE-2015-8560
Security: CVE-2015-8327
 |
17:36 feld
Document py-amf vulnerability
Security: CVE-2015-8549
 |
17:13 feld
Document multiple joomla vulnerabilities
Security: CVE-2015-8562
Security: CVE-2015-8563
Security: CVE-2015-8564
Security: CVE-2015-8565
 |
Wednesday, 16 Dec 2015
|
02:15 feld
Document bind vulnerabilities
Security: CVE-2015-3193
Security: CVE-2015-8000
Security: CVE-2015-8461
 |
01:56 jbeich
Document recent mozilla vulnerabilities
 |
Tuesday, 15 Dec 2015
|
22:06 feld
Document openjdk8 vulnerabilities
PR: 204269
Security: CVE-2015-4908
Security: CVE-2015-4916
Security: CVE-2015-4906
Security: CVE-2015-4872
Security: CVE-2015-4911
Security: CVE-2015-4893
Security: CVE-2015-4803
Security: CVE-2015-4903
Security: CVE-2015-4734
Security: CVE-2015-4842
Security: CVE-2015-4882
Security: CVE-2015-4840
Security: CVE-2015-4902
Security: CVE-2015-4871
Security: CVE-2015-4806
Security: CVE-2015-4810
Security: CVE-2015-4868
Security: CVE-2015-4901
Security: CVE-2015-4844
Security: CVE-2015-4805
Security: CVE-2015-4860
Security: CVE-2015-4883
Security: CVE-2015-4843
Security: CVE-2015-4881
Security: CVE-2015-4835
 |
20:42 ohauer
- fix Additional tests command
o use ./vuln.xml for the sample to work on every location
 |
20:37 ohauer
- document subversion CVE entry
o CVE-2015-5259
o CVE-2015-5343
- adopt new pkg notation on howto check new VID entry
 |
Sunday, 13 Dec 2015
|
21:34 rene
Document new vulnerabilities in www/chromium < 47.0.2526.80
Obtained
from: http://googlechromereleases.blogspot.nl/2015/12/stable-channel-update_8.html
 |
20:23 kwm
* Update the freeimage entry in the dcraw vulnability.
* Document integer overflow in freeimage.
 |
Saturday, 12 Dec 2015
|
18:01 junovitch
Add recent CVE assignment to earlier Git entry in r399700
Security: CVE-2015-7545
Security: https://vuxml.FreeBSD.org/freebsd/7f645ee5-7681-11e5-8519-005056ac623e.html
 |
Friday, 11 Dec 2015
|
00:42 junovitch
Add CVE assignment to the most recent Redmine vulnerability
PR: 205110
Security: CVE-2015-8537
Security: https://vuxml.FreeBSD.org/freebsd/21bc4d71-9ed8-11e5-8f5c-002590263bf5.html
 |
Thursday, 10 Dec 2015
|
01:08 junovitch
Catch up on documentation of Redmine vulnerabilities
PR: 205110
Security: CVE-2015-8346
Security: CVE-2015-8473
Security: CVE-2015-8474
Security: https://vuxml.FreeBSD.org/freebsd/21bc4d71-9ed8-11e5-8f5c-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/3ec2e0bc-9ed7-11e5-8f5c-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/be63533c-9ed7-11e5-8f5c-002590263bf5.html
 |
Wednesday, 9 Dec 2015
|
19:47 lwhsu
Document Jenkins Security Advisory 2015-12-09
 |
Tuesday, 8 Dec 2015
|
19:23 kwm
Document a few, *cough* 78, flash vulnabilities.
Submitted by: xmj@
 |
10:01 brnrd
security/libressl: Update to 2.2.5
- Version 2.2.5 addresses CVE-2015-2394
- Refactor regression-test target to TEST_TARGET
- Add LibreSSL < 2.2.5/2.3.1_1 vuxml entry
Reviewed by: koobs (mentor), feld (ports-secteam), delphij (ports-secteam)
Approved by: koobs (mentor), delphij (ports-secteam)
Security: 215e740e-9c56-11e5-90e7-b499baebfeaf
MFH: 2015Q4
Differential Revision: https://reviews.freebsd.org/D4393
 |
00:34 junovitch
Document additional CVE assigned to incomplete fix png 1.6.19
Security: CVE-2015-8472
Security: CVE-2015-8126
Security: https://vuxml.FreeBSD.org/freebsd/1886e195-8b87-11e5-90e7-b499baebfeaf.html
 |
00:28 junovitch
Document information disclosure in KeePassX
PR: 205105
Security: CVE-2015-8378
Security: https://vuxml.FreeBSD.org/freebsd/918a5d1f-9d40-11e5-8f5c-002590263bf5.html
 |
Monday, 7 Dec 2015
|
23:22 junovitch
Document client controlled header overwriting in Phusion Passenger
PR: 205104
Security: CVE-2015-7519
Security: https://vuxml.FreeBSD.org/freebsd/84fdd1bb-9d37-11e5-8f5c-002590263bf5.html
 |
23:07 junovitch
Wrap earlier libraw entries at 80 characters
 |
23:04 junovitch
Document information disclosure via insecure default permissions in Salt
PR: 205043
Security: CVE-2015-8034
Security: https://vuxml.FreeBSD.org/freebsd/e6b974ab-9d35-11e5-8f5c-002590263bf5.html
 |
11:12 rakuco
Document multiple graphics/libraw vulnerabilities.
Security: CVE-2015-8366
Security: CVE-2015-8367
 |
Saturday, 5 Dec 2015
|
10:16 delphij
Document OpenSSL multiple vulnerabilities.
 |
Thursday, 3 Dec 2015
|
17:08 feld
libpng security fix was not complete. New version released.
Security: 1886e195-8b87-11e5-90e7-b499baebfeaf
Security: CVE-2015-8126
 |
16:23 amdmi3
Document PHPmailer SMTP injection vulnerability
PR: 204500
 |
Wednesday, 2 Dec 2015
|
23:10 jbeich
Document recent ffmpeg vulnerabilities
While here, restore a header line accidentally removed in r402855.
 |
21:49 rene
Doument new vulnerabilities in www/chromium < 47.0.2526.73
Obtained from:
http://googlechromereleases.blogspot.nl/2015/12/stable-channel-update.html
 |
15:39 amdmi3
- Document piwik multiple vulnerabilities
Security: CVE-2015-7815
Security: CVE-2015-7816
 |
Tuesday, 1 Dec 2015
|
14:28 ume
Document Cyrus IMAPd integer overflow vulnerability.
Security: CVE-2015-8077
Security: CVE-2015-8078
 |
Monday, 30 Nov 2015
|
21:38 feld
Document django information leak vulnerability
Security: CVE-2015-8213
 |
Sunday, 22 Nov 2015
|
14:41 junovitch
Document Kibana CSRF attack vulnerability
Security: CVE-2015-8131
Security: https://vuxml.FreeBSD.org/freebsd/fb2475c2-9125-11e5-bd18-002590263bf5.html
 |
02:12 junovitch
Document code execution via a format string vulnerability in a2ps
Security: CVE-2015-8107
Security: https://vuxml.FreeBSD.org/freebsd/e359051d-90bd-11e5-bd18-002590263bf5.html
 |
Friday, 20 Nov 2015
|
20:37 kwm
Document libxslt:
CVE-2015-7995
Document libxml2 :
CVE-2015-5312 CVE-2015-7497 CVE-2015-7498 CVE-2015-7499 CVE-2015-7500
CVE-2015-7941 CVE-2015-7942 CVE-2015-8035 CVE-2015-8241 CVE-2015-8242
 |
00:39 jbeich
Document recent Mozilla vulnerabilities
 |
Wednesday, 18 Nov 2015
|
10:18 kwm
Document gdm lock screen bypass
Security: CVE-2015-7496
 |
Monday, 16 Nov 2015
|
23:46 junovitch
Fix a bad URL caused by an errant 'i' in the <url></url> tags
 |
14:06 garga
Register CVE 2015-8023 on VuXML. It affects strongswan < 5.3.4
 |
02:22 junovitch
Document Moodle multiple security vulnerabilities
Note upstream has not released CVE assignments or details of the issues at
this time. Document the current verbiage from the release notes to help
downstream users proactively update.
Security: https://vuxml.FreeBSD.org/freebsd/82b3ca2a-8c07-11e5-bd18-002590263bf5.html
 |
00:51 junovitch
Document Xen XSA-156
Security: CVE-2015-5307
Security: CVE-2015-8104
Security: https://vuxml.FreeBSD.org/freebsd/2cabfbab-8bfb-11e5-bd18-002590263bf5.html
 |
Sunday, 15 Nov 2015
|
17:28 brnrd
Document vulnerability of libpng
Differential Revision: https://reviews.freebsd.org/D4164
Reviewed By: koobs (mentor)
Approved By: koobs
Security: CVE-2015-8126
 |
Saturday, 14 Nov 2015
|
22:44 kwm
Document latest flash vulnabilities.
Security: CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654
Security: CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658
Security: CVE-2015-7659, CVE-2015-7660, CVE-2015-7661, CVE-2015-7662
Security: CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, CVE-2015-8044
Security: CVE-2015-8046
 |
Wednesday, 11 Nov 2015
|
22:43 rene
Document new vulnerabilities in www/chromium < 46.0.2490.86
Obtained
from: http://googlechromereleases.blogspot.nl/2015/11/stable-channel-update.html
 |
20:39 brnrd
Document CVE's in MySQL/MariaDB/Percona
PR: 204410
Submitted by: Sevan Janiyan <venture37@geeklan.co.uk>
Reviewed by: feld
Approved by: feld
Security: CVE-2015-4802
Security: CVE-2015-4807
Security: CVE-2015-4815
Security: CVE-2015-4826
Security: CVE-2015-4830
Security: CVE-2015-4836
Security: CVE-2015-4858
Security: CVE-2015-4861
Security: CVE-2015-4870
Security: CVE-2015-4913
Security: CVE-2015-4792
 |
16:26 swills
Document RCE in jenkins
 |
11:19 madpilot
Document owncloudclient vulnerability
PR: 204407
Submitted by: Sevan Janiyan <venture37 at geeklan.co.uk>
Security: CVE-2015-7298
 |
03:22 junovitch
Document Xen XSAs-{142,148,149,150,151,152,153}
Security: CVE-2015-7311
Security: CVE-2015-7835
Security: CVE-2015-7969
Security: CVE-2015-7970
Security: CVE-2015-7971
Security: CVE-2015-7972
Security: https://vuxml.FreeBSD.org/freebsd/301b04d7-881c-11e5-ab94-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/3d9f6260-881d-11e5-ab94-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/83350009-881e-11e5-ab94-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/c0e76d33-8821-11e5-ab94-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/e3792855-881f-11e5-ab94-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/e4848ca4-8820-11e5-ab94-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/fc1f8795-881d-11e5-ab94-002590263bf5.html
 |
02:16 junovitch
Document p5-HTML-Scrubber XSS vulnerability
PR: 204416
Reported by: Sevan Janiyan <venture37@geeklan.co.uk>
Security: CVE-2015-5667
Security: https://vuxml.FreeBSD.org/freebsd/2f7f4db2-8819-11e5-ab94-002590263bf5.html
 |
Tuesday, 10 Nov 2015
|
22:26 jbeich
Document MFSA 2015-101 affects multimedia/libvpx as well
PR: 203410
 |
03:25 junovitch
Document CVE assignment on wpa_supplicant 2015-5 advisory
PR: 201432
Security: CVE-2015-8041
Security: https://vuxml.FreeBSD.org/freebsd/c93c9395-25e1-11e5-a4a5-002590263bf5.html
 |
03:18 junovitch
Revise lldpd entry to cover denial of service CVE and add references.
PR: 204044
Security: CVE-2015-8012
Security: CVE-2015-8011
Security: https://vuxml.FreeBSD.org/freebsd/2a4a112a-7c1b-11e5-bd77-0800275369e2.html
 |
Monday, 9 Nov 2015
|
20:57 feld
Document dns/powerdns denial of service vulnerability
Security: CVE-2015-5311
 |
08:06 mandree
Record PuTTY vuln' CVE-2015-5309 (Erase char handling).
 |
Thursday, 5 Nov 2015
|
22:26 truckman
Add openoffice-devel version information to entry
18b3c61b-83de-11e5-905b-ac9e174be3af
Apache OpenOffice 4.1.1 -- multiple vulnerabilities.
 |
17:03 truckman
Apache OpenOffice 4.1.1 -- multiple vulnerabilities.
 |
Wednesday, 4 Nov 2015
|
19:36 zeising
Add CVE for xscreensaver lock bypass.
 |
Sunday, 1 Nov 2015
|
02:10 junovitch
Document multiple vulnerabilities fixed in CodeIgniter
PR: 203403
Security: https://vuxml.FreeBSD.org/freebsd/bdd57272-803c-11e5-ab94-002590263bf5.html
 |
Thursday, 29 Oct 2015
|
01:51 junovitch
Document additional CVE assigned for the last Wordpress update
Security: CVE-2015-7989
Security: https://vuxml.FreeBSD.org/freebsd/f4ce64c2-5bd4-11e5-9040-3c970e169bc2.html
 |
Wednesday, 28 Oct 2015
|
20:59 feld
Document information disclosure in net/openafs
Security: CVE-2015-7762
Security: CVE-2015-7763
 |
Tuesday, 27 Oct 2015
|
20:53 zeising
Add entry for x11/xscreensaver for a lock bypass vulnerability
 |
13:44 mat
Document lldpd security vunlnerability.
PR: 204044
Submitted by: maintainer
Sponsored by: Absolight
 |
Monday, 26 Oct 2015
|
13:45 feld
Update range for libressl vulnerability
Range was entered incorrectly as <2.2.3
Security: e75a96df-73ca-11e5-9b45-b499baebfeaf
 |
Sunday, 25 Oct 2015
|
17:37 marcus
Add an entry for wireshark-1.12.8 for CVE-2015-7830.
 |
03:26 junovitch
Document the recent remote site takeover via SQL injection vuln in Joomla
While here, document all missing Joomla security vulnerabilities since the
last entry in March 2014
Security: CVE-2014-6631
Security: CVE-2014-6632
Security: CVE-2014-7228
Security: CVE-2014-7229
Security: CVE-2015-5397
Security: CVE-2015-5608
Security: CVE-2015-6939
Security: CVE-2015-7297
Security: CVE-2015-7857
Security: CVE-2015-7858
Security: CVE-2015-7859
Security: CVE-2015-7899
Security: https://vuxml.FreeBSD.org/freebsd/0ebc6e78-7ac6-11e5-b35a-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/03e54e42-7ac6-11e5-b35a-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/f8c37915-7ac5-11e5-b35a-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/ec2d1cfd-7ac5-11e5-b35a-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/deaba148-7ac5-11e5-b35a-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/cec4d01a-7ac5-11e5-b35a-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/beb3d5fc-7ac5-11e5-b35a-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/adbb32d9-7ac5-11e5-b35a-002590263bf5.html
 |
Saturday, 24 Oct 2015
|
03:55 junovitch
Document redirect vulnerability in the drupal7 overlay module
PR: 203977
Security: CVE-2015-7943
Security: https://vuxml.FreeBSD.org/freebsd/75f39413-7a00-11e5-a2a1-002590263bf5.html
 |
Friday, 23 Oct 2015
|
20:39 matthew
Record phpMyAdmin -- content spoofing vulnerability.
 |
11:59 delphij
Add CVE references to the NTP entry.
 |
03:43 junovitch
Document Mediawiki security vulnerabilities for 1.25.3, 1.24.4, and 1.23.11
Security: https://vuxml.FreeBSD.org/freebsd/b973a763-7936-11e5-a2a1-002590263bf5.html
 |
Thursday, 22 Oct 2015
|
03:03 cy
Document October 2015 NTP Security Vulnerability Announcement (Medium)
 |
Tuesday, 20 Oct 2015
|
02:33 junovitch
Document multiple XSS vulnerabilities fixed in CodeIgniter
PR: 203403
Security: https://vuxml.FreeBSD.org/freebsd/95602550-76cf-11e5-a2a1-002590263bf5.html
 |
Monday, 19 Oct 2015
|
17:04 garga
Add new VuXML entry for git arbitrary code execution bug on versions before
2.6.1
 |
Saturday, 17 Oct 2015
|
18:16 sunpoet
- Document Salt multiple vulnerabilities
 |
Friday, 16 Oct 2015
|
18:57 swills
Document CVE-2015-7184 in firefox
 |
16:11 kwm
Document flash 0-day, remove code execution.
Security: CVE-2015-7645, CVE-2015-7647, CVE-2015-7648
 |
07:44 peter
Fix the vuxml build caused by a multitude of errors in r399425 (libressl).
 |
07:08 brnrd
security/libressl: Fix memory leak and buffer overflow DoS vulnerability
* Update to 2.2.4 (fixing vulnerabilities)
* Create vuxml entry
Differential revision: https://reviews.freebsd.org/D3916
Submitted by: Bernard Spil <brnrd@freebsd.org>
Reviewed by: delphij (secteam)
Approved by: delphij
MFC after: 2015Q4
Security: CVE-2015-5333, CVE-2015-533
 |
Thursday, 15 Oct 2015
|
14:48 feld
Document vulnerability in polarssl, polarssl13, and mbedtls
Security: CVE-2015-5291
 |
Wednesday, 14 Oct 2015
|
23:59 junovitch
Document multiple vulnerabilities in the Magento platform
While here, update an older entry to reflect Magento was vulnerable
PR: 201709
Security: https://vuxml.FreeBSD.org/freebsd/ea1d2530-72ce-11e5-a2a1-002590263bf5.html
Security: https://vuxml.FreeBSD.org/freebsd/ec34d0c2-1799-11e2-b4ab-000c29033c32.html
Security: CVE-2012-3363
 |
19:02 jbeich
net/miniupnpc: improve TALOS-2015-0035 entry in VuXML
- Add "reserved" CVE link
- Adjust version range to include a few previous snapshots
and different fix in /branches/2015Q4
PR: 203705
 |
17:05 jbeich
net/miniupnpc: reference TALOS-2015-0035 fix
It maybe easier to backport to the quaterly branch than the development
snapshot that caused fallout in most consumers.
PR: 203705
 |
16:53 feld
Document www/pear-twig remote code execution
Security: CVE-2015-7809
 |
16:47 feld
Document assigned CVE for graphics/optipng
Security: CVE-2015-7801
 |
16:21 feld
net/miniupnpc: Document buffer overflow
PR: 203705
Security: TALOS-2015-0035
 |
12:21 kwm
Document latest flash vulnabilities.
Security: CVE-2015-5569, CVE-2015-7625, CVE-2015-7626, CVE-2015-7627,
CVE-2015-7628, CVE-2015-7629, CVE-2015-7630, CVE-2015-7631,
CVE-2015-7632, CVE-2015-7633, CVE-2015-7634, CVE-2015-7643,
CVE-2015-7644
 |
Tuesday, 13 Oct 2015
|
19:31 rene
Forgot two vulnerabilities in the previous commit.
 |
19:28 rene
Document new vulnerabilities in www/chromium < 46.0.2490.71
Obtained
from: http://googlechromereleases.blogspot.nl/2015/10/stable-channel-update.html
 |
Number of commits found: 6273 (showing only 100 on this page) |