notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43  »  [Last Page]

Monday, 23 Jan 2012
21:26 wxs search for other commits by this committer
Whitespace cleanup.
Original commit
21:25 wxs search for other commits by this committer
- Document buffer overflows in spamdyke.
Original commit
14:08 wxs search for other commits by this committer
Fixup to please "make tidy". No need to wrap this line.
Original commit
13:52 wxs search for other commits by this committer
- Add CVE for spamdyke STARTTLS plaintext injection.
Original commit
Sunday, 22 Jan 2012
14:59 sunpoet search for other commits by this committer
- Fix affected rubygem-rack version: add ,3 as PORTEPOCH=3 is restored
Original commit
02:49 zi search for other commits by this committer
- Correct package range in 5c5f19ce-43af-11e1-89b4-001ec9578670
- Add databases/redis to the affected list for
91be81e7-3fea-11e1-afc7-2c4138874f7d
Original commit
Saturday, 21 Jan 2012
01:38 zi search for other commits by this committer
- Fix formatting/topic in 91be81e7-3fea-11e1-afc7-2c4138874f7d

Reviewed by:    wxs
Original commit
Friday, 20 Jan 2012
21:43 zi search for other commits by this committer
- Document security vulnerability in security/openssl (CVE-2012-0050)
Original commit
19:24 jgh search for other commits by this committer
fix uuid on latest tomcat vulnerability

Approved by:    crees, rene (implicit)
Original commit
18:41 delphij search for other commits by this committer
 - Fix modified date;
 - Add more ruby variants.
Original commit
18:28 delphij search for other commits by this committer
Update 91be81e7-3fea-11e1-afc7-2c4138874f7d to cover ruby+no-pthreads as
well.

Spotted by:     Kevin Oberman <kob6558 gmail.com>
Original commit
00:14 flo search for other commits by this committer
- document asterisk remote crash vulnerability
Original commit
Thursday, 19 Jan 2012
19:51 jgh search for other commits by this committer
Document recent vulnerability of Apache Tomcat Server.

Approved by:    rene (mentor)
Original commit
18:33 delphij search for other commits by this committer
Sigh, should have used <lt> instead of <gt>.

Pointy hat to:  delphij
Original commit
18:27 delphij search for other commits by this committer
php52-exif no longer vulnerable to CVE-2011-4566 as of 5.2.17_6
Original commit
09:16 knu search for other commits by this committer
Fix the version range for ruby.  The stock version is affected.
Original commit
09:13 knu search for other commits by this committer
There was no patch release in rubygem-rack 1.3.5_*, so just say < 1.3.6.
Original commit
07:32 sunpoet search for other commits by this committer
- Fix affected rubygem-rack version: it should be _3 for PORTREVISION=3
Original commit
Tuesday, 17 Jan 2012
09:53 danfe search for other commits by this committer
Fix CVE URL in recent OpenTTD entry.
Original commit
08:36 danfe search for other commits by this committer
Unexpand (convert leading spaces to tabs when possible).
Original commit
08:31 danfe search for other commits by this committer
Document recent vulnerability of OpenTTD game server.

Reported by:    Ilya Arkhipov
Original commit
Monday, 16 Jan 2012
09:57 knu search for other commits by this committer
PHP5 had its own entry for this vulnerability, so remove this.

Pointed out by: ohauer
Original commit
03:23 knu search for other commits by this committer
Add node < 0.6.7 (for V8).
Original commit
03:20 knu search for other commits by this committer
Add v8 < 3.8.5 (CVE-2011-5037).
Original commit
03:16 knu search for other commits by this committer
Add PHP < 5.3.9 (CVE-2011-4885).
Original commit
03:03 knu search for other commits by this committer
Add Multiple implementations denial-of-service via hash algorithm collision.

Currently only JRuby, Ruby, and Rack are mentioned.  More to follow.
Original commit
Saturday, 14 Jan 2012
10:01 mm search for other commits by this committer
Add missing URL reference to last commit
Original commit
09:46 mm search for other commits by this committer
Add relevant FFmpeg vulnerabilities from Ubuntu USN-1320-1
Original commit
04:36 miwi search for other commits by this committer
- clean up
Original commit
02:47 zi search for other commits by this committer
- Document vulnerabilities in security/openssl
-- CVE-2011-4108, CVE-2011-4109, CVE-2011-4576
-- CVE-2011-4577, CVE-2011-4619, CVE-2012-0027
Original commit
Friday, 13 Jan 2012
12:10 zi search for other commits by this committer
- Document vulnerability in net/isc-dhcp42-server (CVE-2011-4868)
Original commit
Thursday, 12 Jan 2012
21:56 delphij search for other commits by this committer
Document PowerDNS DoS vulnerability.

PR:             ports/164066
Submitted by:   Ralf van der Enden <tremere cainites.net>
Original commit
Wednesday, 11 Jan 2012
18:32 delphij search for other commits by this committer
Document PHP multiple vulnerabilities.
Original commit
Monday, 9 Jan 2012
18:13 rene search for other commits by this committer
Document a untrusted local library exploit in games/torcs.

Security:       CVE-2010-3384
Original commit
02:26 wxs search for other commits by this committer
Document spamdyke STARTTLS plaintext injection vulnerability.
Original commit
Saturday, 7 Jan 2012
23:44 simon search for other commits by this committer
Remove HTML entity from a VuXML entry as they are not allowed in
VuXML, only Unicode charecter entities are allowed.

This should fix the portaudit build.

If anyone care enough to insert the correct umlaut, feel free to fix.
Original commit
Friday, 6 Jan 2012
18:35 rene search for other commits by this committer
Add new vulnerabilities for www/chromium.

Security:       CVE-2011-[3919,3921-3922]
Original commit
Thursday, 5 Jan 2012
18:52 delphij search for other commits by this committer
Fix build.
Original commit
17:29 ohauer search for other commits by this committer
- document bugzilla and bugzilla3 security issues
Original commit
Tuesday, 3 Jan 2012
23:50 delphij search for other commits by this committer
Document wordpress xss vulnerability.

Feature safe:   yes
Original commit
Friday, 30 Dec 2011
01:05 cy search for other commits by this committer
Add additional MITKRB5 reference.

Security:       MITKRB5-SA-2011-008
Feature safe:   yes
Original commit
Thursday, 29 Dec 2011
14:26 remko search for other commits by this committer
Fix build by adding a reference to the original URL.
Original commit
13:04 crees search for other commits by this committer
Document XSS vulnerability in net-mgmt/zabbix-frontend

PR:             ports/163691
Obtained from:  https://support.zabbix.com/browse/ZBX-4015
Security:       ZBX-4015
Original commit
Wednesday, 28 Dec 2011
12:24 mm search for other commits by this committer
Document remote DoS vulnerability in lighttpd HTTP authentication

Security:       CVS-2011-4362
Original commit
Tuesday, 27 Dec 2011
04:00 eadler search for other commits by this committer
- Fix most of the duplicate words in vuxml, a few affect 'blockquotes' but that
should be okay as no information is lost.
Original commit
Monday, 26 Dec 2011
23:23 wxs search for other commits by this committer
Don't wrap a couple of lines. No other entries wrap these lines, so when
in Rome...
Original commit
23:00 wxs search for other commits by this committer
Whitespace cleanup in a BIND topic.
Original commit
22:42 wxs search for other commits by this committer
Fix the build. Missing a quote on the blockquote citation and a missing </p>.
Original commit
21:51 cy search for other commits by this committer
Document CVE-2011-4862 (FreeBSD-SA-11:08.telnetd) as it affects krb5-appl too.

Security:       CVE-2011-4862, FreeBSD-SA-11:08.telnetd
Feature safe:   yes
Original commit
Friday, 23 Dec 2011
20:37 delphij search for other commits by this committer
Add vuxml entry for proftpd chroot vulnerability.

Feature safe:   yes
Original commit
Thursday, 22 Dec 2011
12:11 zi search for other commits by this committer
- Document recent vulnerabilities in databases/phpmyadmin (PMASA-2011-19 and
PMASA-2011-20)
Original commit
Wednesday, 21 Dec 2011
12:40 beat search for other commits by this committer
- Also fix SeaMonkey version range
Original commit
11:28 beat search for other commits by this committer
- Fix cvename in latest mozilla vulnerability
Original commit
07:48 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
Monday, 19 Dec 2011
13:15 sem search for other commits by this committer
unbound DoS vulnerability
Original commit
Sunday, 18 Dec 2011
14:24 miwi search for other commits by this committer
- Cleanup
        * correct line limit
        * sort cvename
Original commit
13:30 zi search for other commits by this committer
- Correct package name in previous commit

Reported by:    crees@
Original commit
13:07 zi search for other commits by this committer
- Document vulnerabilities in www/typo3 and www/typo345
Original commit
Wednesday, 14 Dec 2011
04:07 zi search for other commits by this committer
- Document security/krb5 vulnerability as described in MITKRB5-SA-2011-007
Original commit
03:52 zi search for other commits by this committer
- Add CVE for recent asterisk vulnerabilities

Feature safe:   yes
Original commit
Tuesday, 13 Dec 2011
20:35 delphij search for other commits by this committer
Document Opera multiple vulnerabilities.

Requested by:   tabthorpe
Feature safe:   yes
Original commit
20:17 rene search for other commits by this committer
Document vulnerabilities fixed in Chromium 16.0.912.63

Security:       CVE-2011-[3903-3917]
Original commit
17:45 mandree search for other commits by this committer
Add cvename tag with content CVE-2011-4607 for PuTTY password 'vulnerability'.

Feature safe: yes
Submitted by: eadler
Original commit
17:34 zi search for other commits by this committer
- Correct package name for asterisk18

Feature safe:   yes
Original commit
Monday, 12 Dec 2011
19:57 mandree search for other commits by this committer
Update PuTTY to new upstream security and bug fix release 0.62,
and add a new VuXML entry.

Changelog:     
http://lists.tartarus.org/pipermail/putty-announce/2011/000017.html
Security:       bbd5f486-24f1-11e1-95bc-080027ef73ec
Feature safe:   yes
Original commit
Friday, 9 Dec 2011
01:52 zi search for other commits by this committer
- Document asterisk vulnerabilities

Feature safe:   yes
Original commit
Wednesday, 7 Dec 2011
23:49 zi search for other commits by this committer
- Document vulnerabilities in isc-dhcp: CVE-2011-4539

Feature safe:   yes
Original commit
Thursday, 1 Dec 2011
21:03 dougb search for other commits by this committer
Update to version 3.4.8

This is the formal release of the fix to CVE-2011-4634, but there are
no code differences from the preliminary fixes released in 3.4.8-rc1
except for the updated version number.

PMSA-2011-18 has now been published; vuxml entry attached.

PR:             ports/163001
Submitted by:   Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)

Feature safe:   yes
Original commit
Wednesday, 30 Nov 2011
09:31 pav search for other commits by this committer
- Add a link to a nice documentation in PH

Suggested by:   dougb
Feature safe:   yes
Original commit
08:45 pav search for other commits by this committer
- Add a quick guide to adding a new entry to this unfriendly file

Feature safe:   yes
Original commit
Saturday, 19 Nov 2011
15:13 dinoex search for other commits by this committer
- mark 1.3.41+2.8.31_4 as not vulnerable
Feature safe:   yes
Original commit
Friday, 18 Nov 2011
22:38 cs search for other commits by this committer
hiawatha -- memory leak in PreventSQLi routine

Approved by:    glarkin@ (mentor)
Feature safe:   yes
Original commit
20:20 delphij search for other commits by this committer
Bump modified date for previous commit.

Feature safe:   yes
Original commit
20:13 dougb search for other commits by this committer
The long-term URL for the latest BIND vulnerability is up at ISC,
so adjust accordingly.

Feature safe:   yes
Original commit
Thursday, 17 Nov 2011
10:08 rene search for other commits by this committer
Mark chromium-15.0.874.120 vulnerable.

Obtained from: 
http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Security:       CVE-2011-3900
Feature safe:   yes
Original commit
Wednesday, 16 Nov 2011
23:59 dougb search for other commits by this committer
Add an entry for the BIND DOS vulnerability announced today

Feature safe:   yes
Original commit
Monday, 14 Nov 2011
23:27 ohauer search for other commits by this committer
- document apache13 CVE-2011-3368

Feature safe:   yes
Original commit
03:25 miwi search for other commits by this committer
- Fix previous entry

Feature safe:   yes
Original commit
03:14 rakuco search for other commits by this committer
Add note about CVE-2011-2725 for ark in kdeutils4.

Approved by:    avilla (mentor, implicit)
Feature safe:   yes
Original commit
Sunday, 13 Nov 2011
22:28 ohauer search for other commits by this committer
- document apache apr-0.9 reimplementation of apr_fnmatch()

Feature safe:   yes
Original commit
02:20 dougb search for other commits by this committer
Fix the recent flash entry:

1. Only one <package> container is needed
2. Use of <lt> has to be relative to the latest (unvulnerable) version
3. Improve the range for the 11.x version to not tag all 10.x versions
4. Use https for the cite in blockquote
5. Fix a CVE entry

Feature safe:   yes
Original commit
Saturday, 12 Nov 2011
16:13 miwi search for other commits by this committer
- Correct latest libxml(1) entrys
- Mark CVS-2009-2414 CVS-2009-2416 CVS-2011-1944 entrys as safe
- Fix whitespaces
- Bump modify date
- While here add missing blank lines between entries [1]

[1] This would not happened when committers use "make newentry" (sometimes RTFM
is really helpful)

Feature safe:   yes
Original commit
12:15 crees search for other commits by this committer
Document latest phpMyAdmin vulnerability

PR:             ports/162442
Submitted by:   Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Security:       CVE-2011-4107
Security:       http://www.phpmyadmin.net/home_page/security/PMASA-2011-17.php
CC:             m.seaman@infracaninophile.co.uk
Feature safe:   yes
Original commit
05:39 eadler search for other commits by this committer
- update flash10 to 10.3r183.11
- add security issues to vuln.xml

Submitted by:   nox
Reviewed by:    dougb (vuxml)
Security:       CVE-2011-2445, CVE-2011-2450, CVE-2011-2451, CVE-2011-2452,
CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, CVE-2011-2456, CVE-2011-2457,
CVE-2011-2458, CVE-2011-2459, CVE-2011-2458

Feature safe:   yesA
Original commit
Friday, 11 Nov 2011
19:13 rene search for other commits by this committer
Add vulnerabilities for www/chromium < 15.0.874.120

Obtained from: 
http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Security:       CVE-2011-[3892-3898]
Feature safe:   yes
Original commit
Thursday, 10 Nov 2011
13:40 wxs search for other commits by this committer
Add missing blank lines between entries.

Feature safe:   yes
Original commit
07:58 delphij search for other commits by this committer
Fix build.

Feature safe:   yes
Original commit
07:19 bapt search for other commits by this committer
Register multiple libxml{1,2} vulnerabilities
Original commit
04:44 miwi search for other commits by this committer
- Cleanup a bit
Original commit
02:27 novel search for other commits by this committer
Document gnutls client session resumption vulnerability.
Original commit
Tuesday, 8 Nov 2011
17:48 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
Monday, 7 Nov 2011
04:27 eadler search for other commits by this committer
- add vuxml entry for insecure use of temporary directories in caml-light

Reviewed by:    dougb
Approved by:    bapt,sahil (mentors, implicit)
Original commit
04:23 eadler search for other commits by this committer
- add vuxml entry for insecure use of temporary directories in caml-light

Reviewed by:    dougb
Approved by:    bapt,sahil (mentors, implicit)
Original commit
Thursday, 3 Nov 2011
21:21 kwm search for other commits by this committer
Fix the freetype entry. The package name is freetype2 and fill in the comment.
Original commit
Tuesday, 1 Nov 2011
18:00 bapt search for other commits by this committer
Fix vuln.xml
Original commit
17:44 kwm search for other commits by this committer
Document vulnerabilities in handling Type 1 fonts in freetype.
Original commit
08:46 delphij search for other commits by this committer
Properly match lower bound of version numbers.

Noticed by:     Patrick Oonk <patrick.oonk pine.nl>
Original commit
07:18 miwi search for other commits by this committer
- bid from latest PivotX entry [1]
- while remove a lot whitespaces

PR:             161734 [1]
Submitted by:   Fumiyuki Shimizu <fumifumi@abacustech.jp>
Original commit
Friday, 28 Oct 2011
17:06 kwm search for other commits by this committer
Document cacti security issues.

SQL injection issue with user login
Cross-site scripting issues.

PR:             ports/162044
Reported by:    moggie <moggie@elasticmind.net>
Original commit
09:28 miwi search for other commits by this committer
- Cleanup & whitespace fixe
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43  »  [Last Page]