notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30  »  [Last Page]

Monday, 12 Oct 2015
14:19 junovitch search for other commits by this committer
Add CVE assignment to r398701 Zend Framework 1 entry

PR:		203462
Security:	CVE-2015-7695
Security:	https://vuxml.FreeBSD.org/freebsd/d3324fdb-6bf0-11e5-bc5e-00505699053e.html
Original commitRevision:399132 
14:11 junovitch search for other commits by this committer
Add CVE assignment to r398626 PHP entry

PR:		203541
Security:	CVE-2015-7804
Security: 	CVE-2015-7803
Security:
	https://vuxml.FreeBSD.org/freebsd/c1da8b75-6aef-11e5-9909-002590263bf5.html
Original commitRevision:399129 
Saturday, 10 Oct 2015
15:27 junovitch search for other commits by this committer
Document shell command execution via improper escaping in p5-UI-Dialog

PR:		203667
Security:	CVE-2008-7315
Security:	https://vuxml.FreeBSD.org/freebsd/00dadbf0-6f61-11e5-a2a1-002590263bf5.html
Original commitRevision:399004 
15:01 junovitch search for other commits by this committer
Document iPython vulnerabilities fixed in 3.2.2

PR:		203668
Security:	CVE-2015-6938
Security:	CVE-2015-7337
Security:	https://vuxml.FreeBSD.org/freebsd/290351c9-6f5c-11e5-a2a1-002590263bf5.html
Original commitRevision:399002 
Thursday, 8 Oct 2015
21:18 girgen search for other commits by this committer
Add entry for two security problems in PostgreSQL

CVE-2015-5289: json or jsonb input values constructed from arbitrary
user input can crash the PostgreSQL server and cause a denial of
service.

CVE-2015-5288: The crypt() function included with the optional pgCrypto
extension could be exploited to read a few additional bytes of memory.
No working exploit for this issue has been developed.
Original commitRevision:398894 
Tuesday, 6 Oct 2015
15:02 wg search for other commits by this committer
security/vuxml: Document Zend Framework 1 vulnerability

PR:		203462
Security:	d3324fdb-6bf0-11e5-bc5e-00505699053e
Security:	CVE-2014-8089
Original commitRevision:398701 
02:54 junovitch search for other commits by this committer
Document OpenSMTPD vulnerabilities (5.7.3)
Revise pkg name, add PORTEPOCH, add more detail to earlier entry (5.7.2)

Security:	42852f72-6bd3-11e5-9909-002590263bf5
Security:	ee7bdf7f-11bb-4eea-b054-c692ab848c20
Security:	CVE-2015-7687
Original commitRevision:398678 
02:24 junovitch search for other commits by this committer
Document recent mbed TLS/PolarSSL security releases

PR:		203544
Security:	5d280761-6bcf-11e5-9909-002590263bf5
Security:	953aaa57-6bce-11e5-9909-002590263bf5
Original commitRevision:398677 
Monday, 5 Oct 2015
11:56 kwm search for other commits by this committer
Unbreak vuxml, woops.
Original commitRevision:398642 
11:46 kwm search for other commits by this committer
Document heap overflows and a DoS in gdk-pixbuf2.

Security:	CVE-2015-7673, CVE-2015-7674
Original commitRevision:398639 
03:09 junovitch search for other commits by this committer
Document 20150910 Plone advisories

PR:		203255
Security:	6b3374d4-6b0b-11e5-9909-002590263bf5
Original commitRevision:398628 
00:00 junovitch search for other commits by this committer
Document PHP multiple security advisories in phar plugin

PR:		203541
Security:	c1da8b75-6aef-11e5-9909-002590263bf5
Original commitRevision:398626 
Sunday, 4 Oct 2015
21:27 junovitch search for other commits by this committer
Add CVE reference to Apache James entry

PR:		203461
Security:	CVE-2015-7611
Security:	be3069c9-67e7-11e5-9909-002590263bf5
Original commitRevision:398624 
14:23 swills search for other commits by this committer
Document mail/opensmtpd vulnerability
Original commitRevision:398575 
Thursday, 1 Oct 2015
03:14 junovitch search for other commits by this committer
Document security advisory for the Apache James server

PR:		203461
Security:	be3069c9-67e7-11e5-9909-002590263bf5
Original commitRevision:398246 
Wednesday, 30 Sep 2015
06:18 cs search for other commits by this committer
Report OTRS vulnerability

Security:	CVE-2015-6842, CVE-2013-7135
Original commitRevision:398203 
Monday, 28 Sep 2015
09:29 kwm search for other commits by this committer
Document newest flash vulnabilities.
Original commitRevision:398105 
02:54 junovitch search for other commits by this committer
Fix <freebsdpr> syntax on several entries

Without ports/ prepended to the PR number, the http://www.vuxml.org links
go to https://bugs.FreeBSD.org and not the actual PR.

While here, "trongSwan" -> "StrongSwan" spelling correction

PR:		200777
Original commitRevision:398071 
01:09 junovitch search for other commits by this committer
Document multiple vulnerabilities in CodeIgniter

PR:		203401
Security:	5114cd11-6571-11e5-9909-002590263bf5
Security:	01bce4c6-6571-11e5-9909-002590263bf5
Security:	c21f4e61-6570-11e5-9909-002590263bf5
Security:	f838dcb4-656f-11e5-9909-002590263bf5
Security:	b7d785ea-656d-11e5-9909-002590263bf5
Original commitRevision:398068 
Sunday, 27 Sep 2015
08:38 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 45.0.2454.101

Obtained
from:	http://googlechromereleases.blogspot.nl/2015/09/stable-channel-update_24.html
Original commitRevision:398028 
Thursday, 24 Sep 2015
02:56 junovitch search for other commits by this committer
Revise Moodle multiple security vulnerabilities from r397210 to reflect
recently published advisory

Security:	CVE-2015-5264
Security:	CVE-2015-5272
Security:	CVE-2015-5265
Security:	CVE-2015-5266
Security:	CVE-2015-5267
Security:	CVE-2015-5268
Security:	CVE-2015-5269
Security:	c2fcbec2-5daa-11e5-9909-002590263bf5
Original commitRevision:397674 
Wednesday, 23 Sep 2015
20:24 feld search for other commits by this committer
Fix older ruby vuxml entry

If you follow official instructions to change your default ruby version
it alters the ruby package name and vuxml will produce false positives.
This change will solve these scenarios.

PR:		203227
Original commitRevision:397659 
Tuesday, 22 Sep 2015
17:26 feld search for other commits by this committer
libssh2 version entry range was missing PORTEPOCH

Security:	9770d6ac-614d-11e5-b379-14dae9d210b8
Original commitRevision:397558 
17:20 feld search for other commits by this committer
Document vulnerability in security/libssh2

Security:	CVE-2015-1782
Original commitRevision:397557 
16:46 jbeich search for other commits by this committer
Summary: Document recent Mozilla vulnerabilities
Original commitRevision:397554 
Sunday, 20 Sep 2015
09:23 jbeich search for other commits by this committer
Mention ports with libzip copy
Original commitRevision:397362 
05:45 jbeich search for other commits by this committer
Fix typo
Original commitRevision:397359 
05:43 jbeich search for other commits by this committer
Next avidemux2 may have CVE-2015-3395 fix, adjust

https://github.com/mean00/avidemux2/commit/cfb9760
Original commitRevision:397358 
05:27 jbeich search for other commits by this committer
Document recent ffmpeg vulnerabilities

libav 11.4 was released before the fixes were made while ffmpeg 2.3.x
and lower are not maintained anymore. Bundle consumers are out of luck
unless low impact there or the fixes are easy to cherry-pick.
Original commitRevision:397357 
Friday, 18 Sep 2015
21:08 cs search for other commits by this committer
Update dcraw entry in VUXML

PR:		203034
Submitted by:	yuri@rawbw.com (maintainer of lightzone)
Security:	57325ecf-facc-11e4-968f-b888e347c638
Original commitRevision:397296 
02:23 junovitch search for other commits by this committer
Document Moodle multiple security vulnerabilities

Note upstream has not released CVE assignments or details of the issues at
this time. Document the current verbiage from the release notes to help
downstream users proactively update.
Original commitRevision:397210 
01:34 junovitch search for other commits by this committer
Document squid TLS/SSL parser denial of service vulnerability

No CVE assigned yet

PR:		203186
Original commitRevision:397209 
00:33 junovitch search for other commits by this committer
Document remind buffer overflow with malicious reminder file input

PR:		202942
Security:	CVE-2015-5957
Original commitRevision:397208 
Thursday, 17 Sep 2015
16:32 feld search for other commits by this committer
Alter <topic> of some of my recent entries to be more consistently worded
Original commitRevision:397127 
16:28 feld search for other commits by this committer
Normalize "use after free" as "use-after-free" in <topic>

I noticed when browsing vuxml.freebsd.org an even split between "use
after free" and "use-after-free". It seemed to make sense to standardize
on one style so future editors will have a common usage to guide them
when new entries are created.
Original commitRevision:397126 
16:16 feld search for other commits by this committer
Document deskutils/shutter vulnerability

Security:	CVE-2015-0854
Original commitRevision:397123 
15:50 feld search for other commits by this committer
Document graphics/openjpeg vulnerability

No CVE assigned yet
Original commitRevision:397121 
14:56 feld search for other commits by this committer
Document vulnerability in older graphics/optipng

No CVE assigned yet
Original commitRevision:397117 
14:50 feld search for other commits by this committer
Document net/openslp vulnerability

Security:	CVE-2015-5155
Original commitRevision:397115 
Wednesday, 16 Sep 2015
20:21 feld search for other commits by this committer
Document archivers/p7zip vulnerability

Security:	CVE-2015-1038
Original commitRevision:397078 
16:32 feld search for other commits by this committer
Document www/h2o vulnerability

PR:		203096
PR:		203147
Security:	CVE-2015-5638
Original commitRevision:397072 
Tuesday, 15 Sep 2015
23:21 delphij search for other commits by this committer
Fix spelling of zh_CN for wordpress vulnerabilities.
Original commitRevision:397029 
18:15 delphij search for other commits by this committer
Document wordpress multiple vulnerabilities.
Original commitRevision:397010 
Monday, 14 Sep 2015
03:59 ohauer search for other commits by this committer
- document bugzilla CVE-2015-4499
Original commitRevision:396877 
Sunday, 13 Sep 2015
19:41 feld search for other commits by this committer
net/openldap24-server Fix affected package name

Submitted by:	dvl
Security:	4910d161-58a4-11e5-9ad8-14dae9d210b8
Original commitRevision:396854 
Saturday, 12 Sep 2015
13:26 feld search for other commits by this committer
Document net/openldap24-server vulnerability

Security:	CVE-2015-6908
Original commitRevision:396744 
Wednesday, 9 Sep 2015
20:41 naddy search for other commits by this committer
Expand a35f415d-572a-11e5-b0a4-f8b156b6dcc8:
multiple vulnerabilities in audio/vorbis-tools and audio/opus-tools
Original commitRevision:396535 
19:53 naddy search for other commits by this committer
Document oggenc buffer overflow in audio/vorbis-tools.

Security:	CVE-2015-6749
Original commitRevision:396531 
14:18 junovitch search for other commits by this committer
Document pgbouncer failed auth_query lookups falling back to auth_user

Note the vulnerable version was not committed to ports, however document
the issue in the interest of being thorough and catching any user who
made this as a local change.

PR:		202957
Security:	CVE-2015-6817
Security:	d76961da-56f6-11e5-934b-002590263bf5
Approved by:	feld (mentor)
Original commitRevision:396503 
Tuesday, 8 Sep 2015
18:49 matthew search for other commits by this committer
Document the latest phpMyAdmin vulnerability: reCaptcha	bypass
Original commitRevision:396427 
18:44 feld search for other commits by this committer
Correct some package names that were mistakenly labeled as php56

Security:	3d675519-5654-11e5-9ad8-14dae9d210b8
Original commitRevision:396426 
18:33 feld search for other commits by this committer
Add assigned CVEs to previous php vulnerability entry

Security:	787ef75e-44da-11e5-93ad-002590263bf5
Security:	CVE-2015-6831
Security:	CVE-2015-6832
Security:	CVE-2015-6833
Original commitRevision:396424 
18:32 feld search for other commits by this committer
Document php vulnerabilities

Security:	CVE-2015-6834
Security:	CVE-2015-6835
Security:	CVE-2015-6836
Security:	CVE-2015-6837
Security:	CVE-2015-6838
Original commitRevision:396423 
17:38 feld search for other commits by this committer
Spelling frontent -> frontend

Security:	d68df01b-564e-11e5-9ad8-14dae9d210b8
Original commitRevision:396417 
17:32 feld search for other commits by this committer
Document sysutils/ganglia-webfrontent vulnerability

Security:	CVE-2015-6816
Original commitRevision:396416 
17:14 feld search for other commits by this committer
Add net/wireshark-qt5 as affected

Security:	9bdd8eb5-564a-11e5-9ad8-14dae9d210b8
Original commitRevision:396415 
17:10 feld search for other commits by this committer
Document net/wireshark vulnerabilities

Security:	CVE-2015-6241
Security:	CVE-2015-6242
Security:	CVE-2015-6243
Security:	CVE-2015-6244
Security:	CVE-2015-6245
Security:	CVE-2015-6246
Security:	CVE-2015-6247
Security:	CVE-2015-6248
Security:	CVE-2015-6249
Original commitRevision:396413 
16:34 feld search for other commits by this committer
Document sysutils/screen vulnerability

Security:	CVE-2015-6806
Original commitRevision:396407 
16:18 feld search for other commits by this committer
Document net/libvncserver vulnerability
Old issue ignored in RH bugzilla; CVE recently requested
Original commitRevision:396404 
Friday, 4 Sep 2015
17:37 kwm search for other commits by this committer
Document a number of integer overflows in gdk-pixbuf2.
Original commitRevision:396123 
Thursday, 3 Sep 2015
15:23 feld search for other commits by this committer
Minimum range adjustment for bind vulnerability

Pointyhat:	firmly seated on head
Submitted by:	mat
Security:	CVE-2015-5986
Security:	2c5e7e23-5248-11e5-9ad8-14dae9d210b8
Original commitRevision:395968 
15:15 feld search for other commits by this committer
Correct version range mistakes in bind vulnerabilities

Submitted by:	mat
Security:	2c5e7e23-5248-11e5-9ad8-14dae9d210b8
Security:	eaf3b255-5245-11e5-9ad8-14dae9d210b8
Original commitRevision:395966 
14:34 feld search for other commits by this committer
Document bind vulnerabilities

Security:	CVE-2015-5986
Security:	CVE-2015-5722
Original commitRevision:395962 
Wednesday, 2 Sep 2015
18:06 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 45.0.2454.85

Submitted by:	Carlos Jacobo Puga Medina
Obtained from:	http://googlechromereleases.blogspot.nl/
Original commitRevision:395903 
16:37 feld search for other commits by this committer
Document dns/powerdns vulnerability

PR:		202738
Security:	CVE-2015-5230
Original commitRevision:395862 
00:30 junovitch search for other commits by this committer
Revise Ghostscript entry date to match date of commit.

Approved by:	delphij (mentor)
Original commitRevision:395811 
Tuesday, 1 Sep 2015
22:12 junovitch search for other commits by this committer
Document denial of service (crash) via crafted Postscript files for Ghostscript

PR:		202781
Security:	CVE-2015-3228
Security:	fc1f6658-4f53-11e5-934b-002590263bf5
Approved by:	feld (mentor)
Original commitRevision:395802 
13:42 jbeich search for other commits by this committer
Document recent ffmpeg/libav vulnerabilities
Original commitRevision:395752 
Saturday, 29 Aug 2015
15:23 feld search for other commits by this committer
Document graphics/graphviz vulnerability
No CVE assigned
Original commitRevision:395559 
Friday, 28 Aug 2015
12:34 jbeich search for other commits by this committer
Document recent mozilla vulnerabilities
Original commitRevision:395469 
Wednesday, 26 Aug 2015
14:25 feld search for other commits by this committer
graphics/libpgf was assigned a CVE

Security:	9a71953a-474a-11e5-adde-14dae9d210b8
Security:	CVE-2015-6673
Original commitRevision:395363 
Tuesday, 25 Aug 2015
22:46 junovitch search for other commits by this committer
Document multiple security advisories for go and go14

PR:		202633
Security:	CVE-2015-5739
Security:	CVE-2015-5740
Security:	CVE-2015-5741
Security:	4464212e-4acd-11e5-934b-002590263bf5
Approved by:	delphij (mentor)
Original commitRevision:395321 
09:57 jbeich search for other commits by this committer
Fix MFSA quote link and add libtremor commits
Original commitRevision:395225 
07:10 jbeich search for other commits by this committer
Document libtremor vulnerabilities in the ancient version we provide
Original commitRevision:395220 
Monday, 24 Aug 2015
16:10 feld search for other commits by this committer
Document devel/pcre vulnerability

Security:	6900e6f1-4a79-11e5-9ad8-14dae9d210b8
Original commitRevision:395177 
Saturday, 22 Aug 2015
07:08 delphij search for other commits by this committer
Document drupal multiple vulnerabilities.
Original commitRevision:395017 
Friday, 21 Aug 2015
22:06 bdrewery search for other commits by this committer
Remove excess space
Original commitRevision:394998 
22:05 bdrewery search for other commits by this committer
Document OpenSSH 7.0 PAM fixes.

It is unclear from the announcement what the minimum version affected
was.
Original commitRevision:394997 
22:01 bdrewery search for other commits by this committer
Document OpenSSH 7.0 PermitRootLogin issue
Original commitRevision:394996 
14:23 feld search for other commits by this committer
Document sysutils/tarsnap security announcement
Original commitRevision:394956 
Thursday, 20 Aug 2015
17:30 delphij search for other commits by this committer
Document vlc arbitrary pointer dereference.
Original commitRevision:394900 
15:12 feld search for other commits by this committer
graphics/jasper new CVE added to entry

Security:	f1692469-45ce-11e5-adde-14dae9d210b8
Security:	CVE-2015-5221
Original commitRevision:394886 
14:56 feld search for other commits by this committer
Document vulnerability in graphics/libpgf
No CVE assigned yet
Original commitRevision:394884 
00:54 peter search for other commits by this committer
Look up a reference to a commit in 2005 that had been previously lost.
Original commitRevision:394820 
00:41 peter search for other commits by this committer
Update some legacy items that don't work or are using runtime remapping:
- cvsweb -> svnweb
- stray cgi query-pr -> xml pr references
- remove redundant formatting that references obsolete cgi scripts.

Should be cosmetic and reduce some http redirects.
Original commitRevision:394819 
Wednesday, 19 Aug 2015
22:06 junovitch search for other commits by this committer
Extend recent QEMU related xen-tools CVEs to include the qemu-* ports

PR:		202402
Security:	CVE-2015-5154
Security:	CVE-2015-5165
Security:	CVE-2015-5166
Security:	da451130-365d-11e5-a4a5-002590263bf5
Security:	f06f20dc-4347-11e5-93ad-002590263bf5
Security:	ee99899d-4347-11e5-93ad-002590263bf5
Approved by:	feld (mentor)
Original commitRevision:394816 
10:39 kwm search for other commits by this committer
Document CVE-2015-4491 in gdk-pixbuf2.
Original commitRevision:394772 
Tuesday, 18 Aug 2015
18:44 feld search for other commits by this committer
irc/unreal fix <name> to be capitalized

Security:	0ecc1f55-45d0-11e5-adde-14dae9d210b8
Original commitRevision:394636 
18:12 feld search for other commits by this committer
Document django vulnerabilities

Security:	CVE-2015-5963
Security:	CVE-2015-5964
Original commitRevision:394629 
17:45 feld search for other commits by this committer
Document irc/unreal denial of service
No CVE assigned yet
Original commitRevision:394627 
17:37 feld search for other commits by this committer
Document graphics/jasper vulnerability

Security:	CVE-2015-5203
Original commitRevision:394623 
17:27 feld search for other commits by this committer
Document freexl multiple vulnerabilities. One is still awaiting CVE assignment.

Security:	CVE-2015-2776
Original commitRevision:394622 
17:12 feld search for other commits by this committer
rt was assigned a CVE

Security:	83b38a2c-413e-11e5-bfcf-6805ca0b3d42
Security:	CVE-2015-6506
Original commitRevision:394621 
17:10 feld search for other commits by this committer
ansible was assigned a CVE

Security:	72fccfdf-2061-11e5-a4a5-002590263bf5
Security:	CVE-2015-6240
Original commitRevision:394620 
17:08 feld search for other commits by this committer
gnutls was assigned a CVE

Security:	ec6a2a1e-429d-11e5-9daa-14dae9d210b8
Security:	CVE-2015-6251
Original commitRevision:394619 
Monday, 17 Aug 2015
16:25 feld search for other commits by this committer
Document mod_jk vulnerability

Security:	CVE-2014-8111
Original commitRevision:394518 
13:51 junovitch search for other commits by this committer
Document two QEMU related xen-tools security advisories

PR:		201931
Security:	CVE-2015-5166
Security:	ee99899d-4347-11e5-93ad-002590263bf5
Security:	CVE-2015-5165
Security:	f06f20dc-4347-11e5-93ad-002590263bf5
Approved by:	feld (mentor)
Original commitRevision:394505 
13:44 junovitch search for other commits by this committer
Document PHP security issues impacting the lang/php5* ports (Core/SPL)
and 3 extensions (OpenSSL, Phar, SOAP)

PR:		202386
Security:	787ef75e-44da-11e5-93ad-002590263bf5
Approved by:	feld (mentor)
Original commitRevision:394504 
Friday, 14 Aug 2015
17:09 junovitch search for other commits by this committer
Document MediaWiki multiple security vulnerabilities

PR:		202328
Security:	6241b5df-42a1-11e5-93ad-002590263bf5
Approved by:	feld (mentor)
Original commitRevision:394240 
16:38 jbeich search for other commits by this committer
Sync libvpx check for CVE-2015-448[56] with r394231
Original commitRevision:394232 

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30  »  [Last Page]