notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33  »  [Last Page]

Sunday, 26 Apr 2015
06:34 delphij search for other commits by this committer
Document PHP multiple vulnerabilities.

Submitted by:	Bernard Spil <spil.oss gmail com>
Original commitRevision:384755 
Friday, 24 Apr 2015
16:52 kwm search for other commits by this committer
There are actualy two chinese wordpress ports, which have both different
suffixes. List them both.
Original commitRevision:384667 
15:42 kwm search for other commits by this committer
Add wordpress vulnabilities.
Original commitRevision:384661 
Wednesday, 22 Apr 2015
07:40 novel search for other commits by this committer
Add an entry for security/libtasn1 vulnerability.

Security:	CVE-2015-2806
Original commitRevision:384480 
Tuesday, 21 Apr 2015
02:41 jbeich search for other commits by this committer
Document new Firefox vulnerability. CVE-2015-2706
Original commitRevision:384402 
Saturday, 18 Apr 2015
10:17 jbeich search for other commits by this committer
Document sqlite3 multiple vulnerabilites

PR:		199483
Original commitRevision:384217 
09:27 jbeich search for other commits by this committer
Document chrony multiple vulnerabilites.

PR:		199508
Original commitRevision:384214 
Friday, 17 Apr 2015
22:11 jbeich search for other commits by this committer
Document new Dulwich vulnerability. CVE-2015-0838

PR:		199162
Submitted by:	Marco Broder (maintainer)
Original commitRevision:384191 
10:09 xmj search for other commits by this committer
Register Flash vulnerabilities.
Affected: www/linux-*-flashplugin11.
Original commitRevision:384147 
08:04 jbeich search for other commits by this committer
Document Wesnoth vulnerability. CVE-2015-0844

PR:		199414
Original commitRevision:384141 
Tuesday, 14 Apr 2015
08:33 rakuco search for other commits by this committer
Add entry for CVE-2015-1858, CVE-2015-1859 and CVE-2015-1860.

Multiple vulnerabilities in Qt image format handling (the 3 CVEs are part of
the same security advisory).
Original commitRevision:383985 
00:50 swills search for other commits by this committer
Document issues in ruby
Original commitRevision:383968 
Thursday, 9 Apr 2015
19:35 mandree search for other commits by this committer
Add mailman < 2.1.20 vulnerability.

Port update to arrive shortly.
Original commitRevision:383670 
Wednesday, 8 Apr 2015
21:46 madpilot search for other commits by this committer
Document new asterisk ports vulnerability.
Original commitRevision:383608 
Tuesday, 7 Apr 2015
23:48 delphij search for other commits by this committer
Document NTP multiple vulnerabilities.
Original commitRevision:383551 
Friday, 3 Apr 2015
23:42 jbeich search for other commits by this committer
Document mozilla vulnerabilities in Firefox 37.0
Original commitRevision:383181 
16:34 riggs search for other commits by this committer
Document multiple vulnerabilities in multimedia/libav prior to version 11.3

PR:		198873
Submitted by:	venture37@geeklan.co.uk
MFH:		2015Q2
Original commitRevision:383146 
Wednesday, 1 Apr 2015
20:03 delphij search for other commits by this committer
Document multiple vulnerabilities of PHP.

Submitted by:	Bernard Spil <bernard bachfreund nl>
Original commitRevision:382948 
Tuesday, 31 Mar 2015
20:16 ohauer search for other commits by this committer
- document subversion issues
  http://subversion.apache.org/security/

Security:	 CVE-2015-0202
Security:	 CVE-2015-0248
Security:	 CVE-2015-0251
Original commitRevision:382862 
18:40 jbeich search for other commits by this committer
Document mozilla vulnerabilities
Original commitRevision:382858 
16:10 amdmi3 search for other commits by this committer
Add vulnerability for devel/osc.

Security:	CVE-2015-0778
PR:		198876
Submitted by:	venture37@geeklan.co.uk
Original commitRevision:382847 
14:51 naddy search for other commits by this committer
Document GNU cpio vulnerabilities CVE-2014-9112 and CVE-2015-1197.
Original commitRevision:382827 
Saturday, 28 Mar 2015
16:50 makc search for other commits by this committer
Document libzip vulnerability CVE-2015-2331
Original commitRevision:382524 
Friday, 27 Mar 2015
05:33 lwhsu search for other commits by this committer
Document django vulnerability CVE-2015-2316 and CVE-2015-2317
Original commitRevision:382361 
Wednesday, 25 Mar 2015
13:13 dvl search for other commits by this committer
Revert my previous commit.
Original commitRevision:382214 
13:03 dvl search for other commits by this committer
Convert non-ASCII quotes to ASCII characters

Approved by: mat (mentor)
Original commitRevision:382212 
Tuesday, 24 Mar 2015
23:20 jgh search for other commits by this committer
- fixing package name

$ make -C /usr/ports/devel/mingw64-binutils/ -V PKGNAME
x86_64-pc-mingw32-binutils-2.23.2_1
Original commitRevision:382188 
22:15 zi search for other commits by this committer
- Fix vuxml build: bad package names in f6a014cd-d268-11e4-8339-001e679db764
- Fix blockquote style to match rest
Original commitRevision:382184 
21:32 brooks search for other commits by this committer
The ancient version of binutils in the cross-binutils port suffers for
several vulnerabilities.

This also effects devel/mingw64-binutils.

PR:		198816
Reported by:	Sevan Janiyan <venture37@geeklan.co.uk>
Original commitRevision:382177 
16:11 vanilla search for other commits by this committer
Document nodejs (libuv) CVE-2015-0278.

PR:		198861
Submitted by:	venture37@geeklan.co.uk
Original commitRevision:382113 
12:17 xmj search for other commits by this committer
Document vulnerable linux-c6-openssl versions in vuxml entry from 2015-03-19

Approved by:    swills (mentor)
Original commitRevision:382085 
06:22 lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2015-03-23
Original commitRevision:382070 
Sunday, 22 Mar 2015
04:45 jbeich search for other commits by this committer
Document mozilla issues disclosed at HP Zero Day Initiative's Pwn2Own
Original commitRevision:381888 
Thursday, 19 Mar 2015
22:54 delphij search for other commits by this committer
Mention LibreSSL too.  Use <ul>'s per suggestion from vsevolod [1].

PR:		198718 [1]
Original commitRevision:381700 
21:21 delphij search for other commits by this committer
Document OpenSSL multiple vulnerabilities.
Original commitRevision:381694 
Wednesday, 18 Mar 2015
09:07 kwm search for other commits by this committer
Record new libXfont security issues.
Original commitRevision:381528 
Monday, 16 Mar 2015
17:01 xmj search for other commits by this committer
Add latest security vulnerabilities in linux-*-flashplugin11:

	CVE-2015-0332
	CVE-2015-0333
	CVE-2015-0334
	CVE-2015-0335
	CVE-2015-0336
	CVE-2015-0337
	CVE-2015-0338
	CVE-2015-0339
	CVE-2015-0340
	CVE-2015-0341
	CVE-2015-0342

Differential Revision:	https://reviews.freebsd.org/D2061
Approved by:		swills (mentor)
Original commitRevision:381427 
Friday, 13 Mar 2015
04:08 brd search for other commits by this committer
Add vulnerability for mail/sympa.

Approved by:	bapt
Security:	CVE-2015-1306
Original commitRevision:381163 
Sunday, 8 Mar 2015
11:55 matthew search for other commits by this committer
Document latest security vulnerabilities in rt42 and rt40:

      CVE-2014-9472
      CVE-2015-1165
      CVE-2015-1464
Original commitRevision:380770 
11:41 matthew search for other commits by this committer
Document the latest phpMyAdmin vulnerability:  CVE-2015-2206
Original commitRevision:380768 
Saturday, 7 Mar 2015
17:17 romain search for other commits by this committer
Document mono TLS bugs.

Reported by:	delphij
Original commitRevision:380709 
Thursday, 5 Mar 2015
22:10 mandree search for other commits by this committer
Document recently fixed PuTTY < 0.64 vuln. CVE-2015-2157.
Original commitRevision:380553 
Wednesday, 4 Mar 2015
23:18 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 41.0.2272.76

Submitted by:	Carlos Jacobo Puga Medina
Obtained from:	http://googlechromereleases.blogspot.nl/
Original commitRevision:380453 
23:05 rakuco search for other commits by this committer
Add entry for CVE-2015-0295 in qt4-gui and qt5-gui.
Original commitRevision:380451 
Sunday, 1 Mar 2015
03:42 swills search for other commits by this committer
Add entry for security issue in jenkins

Reviewed by:	zi
Original commitRevision:380172 
Friday, 27 Feb 2015
08:28 jbeich search for other commits by this committer
Fix typo: s/MSFA/MFSA/. The source to follow later.

https://bugzilla.mozilla.org/show_bug.cgi?id=1137604
Original commitRevision:380068 
07:14 jbeich search for other commits by this committer
Document mozilla vulnerabilities
Original commitRevision:380065 
Thursday, 26 Feb 2015
19:58 brd search for other commits by this committer
Document vulnerablities in php for CVE-2015-0235 and CVE-2015-0273.

Approved by:	zi (mentor)
Original commitRevision:380052 
01:12 cy search for other commits by this committer
Document bugs fixed in krb5 1.11.6.

* Handle certain invalid RFC 1964 GSS tokens correctly to avoid
  invalid memory reference vulnerabilities.  [CVE-2014-4341
  CVE-2014-4342]

* Fix memory management vulnerabilities in GSSAPI SPNEGO.
  [CVE-2014-4343 CVE-2014-4344]

* Fix buffer overflow vulnerability in LDAP KDB back end.
  [CVE-2014-4345]

* Fix multiple vulnerabilities in the LDAP KDC back end.
  [CVE-2014-5354 CVE-2014-5353]

* Fix multiple kadmind vulnerabilities, some of which are based in the
  gssrpc library. [CVE-2014-5352 CVE-2014-9421 CVE-2014-9422
  CVE-2014-9423]

Security:	CVE-2014-4341, CVE-2014-4342, CVE-2014-4343, CVE-2014-4344
		CVE-2014-4345, CVE-2014-5354, CVE-2014-5353, CVE-2014-5352
		CVE-2014-9421, CVE-2014-9422, CVE-2014-9423
Original commitRevision:379968 
Tuesday, 24 Feb 2015
00:54 delphij search for other commits by this committer
Document Samba remote code execution vulnerability.
Original commitRevision:379719 
00:20 mandree search for other commits by this committer
Record two e2fsprogs vulnerabilities.CVE-2015-0247
    <URL:http://vuxml.freebsd.org/0f488b7b-bbb9-11e4-903c-080027ef73ec.html>

    Topic: e2fsprogs -- potential buffer overflow in closefs()
    Affects:
        e2fsprogs < 1.42.12_2
	References:
	   
url:http://git.kernel.org/cgit/fs/ext2/e2fsprogs.git/commit/?h=maint&id=49d0fe2a14f2a23da2fe299643379b8c1d37df73
	        cvename:CVE-2015-1572
		<URL:http://vuxml.freebsd.org/2a4bcd7d-bbb8-11e4-903c-080027ef73ec.html>

Security:	CVE-2015-0247
Security:	CVE-2015-1572
Security:	0f488b7b-bbb9-11e4-903c-080027ef73ec
Security:	2a4bcd7d-bbb8-11e4-903c-080027ef73ec.html
Original commitRevision:379718 
Monday, 23 Feb 2015
22:13 delphij search for other commits by this committer
Document BIND DoS issue with trust anchor management.
Original commitRevision:379713 
Saturday, 21 Feb 2015
16:12 cy search for other commits by this committer
Kerberos Version 5, Release 1.12.3 is released affecting
security/krb5-112. This fixes multiple vulnerabilities, some previously
committed by point patches and others newly fixed in this release.

* Fix multiple vulnerabilities in the LDAP KDC back end.
  [CVE-2014-5354] [CVE-2014-5353]

* Fix multiple kadmind vulnerabilities, some of which are based in the
  gssrpc library. [CVE-2014-5352 CVE-2014-5352 CVE-2014-9421
  CVE-2014-9422 CVE-2014-9423]

Security:	CVE-2014-5354, CVE-2014-5353
Security:	CVE-2014-5352, CVE-2014-5352, CVE-2014-9421
Security:	CVE-2014-9422, CVE-2014-9423
Original commitRevision:379531 
Tuesday, 17 Feb 2015
22:03 delphij search for other commits by this committer
Document unzip heap based buffer overflow in iconv patch.

PR:		ports/197772
Original commitRevision:379193 
17:19 madpilot search for other commits by this committer
Add modified date to entries I touched recently.

Noticed by:	kwm (thanks)
Original commitRevision:379183 
16:14 madpilot search for other commits by this committer
Add CVE number to asterisk advisory.
Original commitRevision:379176 
Friday, 13 Feb 2015
20:23 cy search for other commits by this committer
Backported patches for CVE-2014-5353 and CVE-2014-5354 received from MIT
for krb5-111 and krb5-112.

Obtained from:	Greg Hudson <ghudson@mit.edu>
Security:	CVE-2014-5353, CVE-2014-5354
Original commitRevision:378943 
01:59 zi search for other commits by this committer
- Additional fixes from the krb5 commit
Original commitRevision:378911 
01:55 zi search for other commits by this committer
- Correct errors in previous commit to resolve build
Original commitRevision:378910 
01:45 cy search for other commits by this committer
Document new krb5 vulnerabilities.

Security:	CVE-2014-5353, CVE-2014-5354
Original commitRevision:378908 
Thursday, 12 Feb 2015
21:00 kwm search for other commits by this committer
The xorg-server entry in commit 378888, also mention portepoch for the other
version we want to check.
Original commitRevision:378896 
19:56 kwm search for other commits by this committer
Document xorg-server CVE-2015-0255.

Information leak in the XkbSetGeometry request of X servers
Original commitRevision:378888 
Monday, 9 Feb 2015
08:23 girgen search for other commits by this committer
In r378499, PostgreSQL package names where not version-suffixed. Fixed this.
Submitted by:	kuriyama@
Original commitRevision:378717 
Friday, 6 Feb 2015
23:27 rene search for other commits by this committer
Fix CVE name for www/chromium entry

Submitted by:	bz via bot
Original commitRevision:378570 
22:48 delphij search for other commits by this committer
Document two recent OpenLDAP DoS issues.
Original commitRevision:378567 
22:21 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 40.0.2214.111

Submitted by:	Carlos Jacobo Puga Medina
Obtained from:	http://googlechromereleases.blogspot.nl/
Original commitRevision:378560 
Thursday, 5 Feb 2015
22:54 girgen search for other commits by this committer
Update PostgreSQL-9.x to latests versions.

This update fixes multiple security issues reported in PostgreSQL over the past
few months. All of these issues require prior authentication, and some require
additional conditions, and as such are not considered generally urgent.
However, users should examine the list of security holes patched below in case
they are particularly vulnerable.

Security:	CVE-2015-0241,CVE-2015-0242,CVE-2015-0243,
		CVE-2015-0244,CVE-2014-8161
Original commitRevision:378499 
08:57 tijl search for other commits by this committer
Remove 734bcd49-aae6-11e4-a0c1-c485083ca99c because Adobe Flash Player 11.x
isn't affected.  See February 2 revision of
https://helpx.adobe.com/security/products/flash-player/apsa15-02.html
Original commitRevision:378447 
Wednesday, 4 Feb 2015
20:38 cy search for other commits by this committer
Add the following KRB5 CVEs.

CVE-2014-5352: gss_process_context_token() incorrectly frees context

CVE-2014-9421: kadmind doubly frees partial deserialization results

CVE-2014-9422: kadmind incorrectly validates server principal name

CVE-2014-9423: libgssrpc server applications leak uninitialized bytes

Security:	CVE-2014-5352, CVE-2014-9421, CVE-2014-9422, CVE-2014-9423
Original commitRevision:378415 
Tuesday, 3 Feb 2015
22:35 delphij search for other commits by this committer
Document unzip out of boundary access issues in test_compr_eb.

PR:		ports/197300
Original commitRevision:378381 
Monday, 2 Feb 2015
19:09 xmj search for other commits by this committer
Add linux-f10-devtools (any version) and linux-c6-devtools (prior to 6.6_3) to
the CVE-2015-0235 entry from 2015-01-28.

Approved by:	swills (mentor)
Original commitRevision:378319 
15:25 feld search for other commits by this committer
Add net-mgmt/xymon-server CVE-2015-1430
Original commitRevision:378307 
14:53 xmj search for other commits by this committer
www/linux-*-flashplugin11: Add CVE-2015-0313

Spotted by:	kwm
Approved by:	swills (mentor)
Original commitRevision:378306 
Saturday, 31 Jan 2015
16:09 olgeni search for other commits by this committer
Add CVE-2015-0862 for net/rabbitmq.
Original commitRevision:378218 
15:07 ohauer search for other commits by this committer
- document apache24 issues
Original commitRevision:378212 
Thursday, 29 Jan 2015
11:20 madpilot search for other commits by this committer
Document asterisk security issues.

While here, add CVE number to a previous asterisk entry.
Original commitRevision:378113 
Wednesday, 28 Jan 2015
08:39 xmj search for other commits by this committer
Add CVE-2015-0235.

- Affects linux_base-*

Approved by:	so@ (des)
Original commitRevision:378048 
Monday, 26 Jan 2015
21:20 tijl search for other commits by this committer
Document critical Adobe Flash Player vulnerability (CVE-2015-0311)
Original commitRevision:377958 
20:24 ohauer search for other commits by this committer
- document bugzilla security issues
Original commitRevision:377951 
Saturday, 24 Jan 2015
17:58 lwhsu search for other commits by this committer
- Fix description of 9c7b6c20-a324-11e4-879c-00e0814cab4e
Original commitRevision:377804 
Friday, 23 Jan 2015
17:47 lwhsu search for other commits by this committer
Document Django 2014-01-13 vulnerabilty
Original commitRevision:377750 
Thursday, 22 Jan 2015
17:43 mi search for other commits by this committer
Add a note about the just-fixed vulnerability of applications using net/libutp.

PR:		196351
Differential Revision:	D1575
Submitted by:	Jan Beich
Approved by:	bapt
Original commitRevision:377675 
17:09 xmj search for other commits by this committer
Amend linux-c6-openssl version in OpenSSL entry from 2015-01-08.

Approved by:	swills (mentor)
Original commitRevision:377670 
17:02 vsevolod search for other commits by this committer
Add CVE-2015-0206 description for LibreSSL port.
Original commitRevision:377669 
12:54 tijl search for other commits by this committer
Document Adobe Flash Player vulnerabilities
Original commitRevision:377652 
Wednesday, 21 Jan 2015
22:09 rene search for other commits by this committer
Document new vulnerabilities in www/chromium < 40.0.2214.91

Also affects FFmpeg, ICU, DOM but the links on the webpage all result in a 403.

Obtained from:	http://googlechromereleases.blogspot.nl
Original commitRevision:377627 
Monday, 19 Jan 2015
20:52 jase search for other commits by this committer
security/vuxml:
- Document security/polarssl and security/polarssl13 crafted certificates
  vulnerability (CVE-2015-1182)
Original commitRevision:377478 
Friday, 16 Jan 2015
08:18 ehaupt search for other commits by this committer
Document multiple archivers/unzip vulnerabilities (CVE-2014-8139,
CVE-2014-8140, CVE-2014-8141).

PR:		196777 (based on)
Submitted by:	rsimmons0@gmail.com
Original commitRevision:377155 
04:05 timur search for other commits by this committer
Add description of CVE-2014-8143 in net/samba4 and net/samba41
Original commitRevision:377152 
Wednesday, 14 Jan 2015
21:54 rakuco search for other commits by this committer
Add entry for CVE-2013-7252 in x11/kde4-runtime.
Original commitRevision:377053 
07:10 beat search for other commits by this committer
Document mozilla vulnerabilities
Original commitRevision:376998 
Sunday, 11 Jan 2015
19:39 mm search for other commits by this committer
Add vuln.xml entry for libevent CVE-2014-6272

PR:	ports/199640
Original commitRevision:376799 
Friday, 9 Jan 2015
18:56 sunpoet search for other commits by this committer
- Fix more typo
Original commitRevision:376644 
18:51 sunpoet search for other commits by this committer
- Fix typo
Original commitRevision:376643 
18:41 sunpoet search for other commits by this committer
- Document cURL URL request injection vulnerability (CVE-2014-8150)
Original commitRevision:376640 
13:35 kwm search for other commits by this committer
Document webkit-gtk[23] vulnabilities.
Original commitRevision:376608 
00:00 delphij search for other commits by this committer
Document OpenSSL multiple vulnerabilities.
Original commitRevision:376575 
Tuesday, 6 Jan 2015
21:11 mandree search for other commits by this committer
Add three upstream patches to busybox 1.22.1, bumping PORTREVISION to 2.
One fixes the CVE-2014-4608 buffer overrun in LZO2,
one fixes the nc app, one fixes the zcat and related apps when accessing
files without extension.

List busybox < 1.22.1_2 as vulnerable, and add CVE Name to the vulndb.

Security:	CVE-2014-4608
Security:	d1f5e12a-fd5a-11e3-a108-080027ef73ec
Original commitRevision:376441 
Sunday, 4 Jan 2015
22:54 rea search for other commits by this committer
VuXML: document multiple vulnerabilities in WordPress

CVE-2014-9033 to CVE-2014-9039.
Original commitRevision:376278 
22:25 rea search for other commits by this committer
VuXML: document heap overflow in 32-bit builds of libpng
Original commitRevision:376276 

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33  »  [Last Page]