notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46  »  [Last Page]

Saturday, 8 Jan 2011
06:54 rea search for other commits by this committer
Document CVE-2010-4345: local exim -> root escalation

PR: 152983
Feature safe: yes
Reviewed by: remko (secteam)
Approved by: erwin (mentor), remko (secteam)
Original commit
Thursday, 6 Jan 2011
07:01 miwi search for other commits by this committer
- Cleanup
Original commit
06:35 wen search for other commits by this committer
- Document the Clickjacking vulnerabilities of mediawiki
Original commit
Saturday, 1 Jan 2011
14:31 erwin search for other commits by this committer
Bump copyright year.
Original commit
Thursday, 30 Dec 2010
17:13 kwm search for other commits by this committer
Document webkit-gtk2 multiple vulnerabilities < 1.2.6.

Document some CVE's that didn't make it to release notes from older releases.
Original commit
Wednesday, 29 Dec 2010
19:50 delphij search for other commits by this committer
Document django multiple vulnerabilities.
Original commit
Tuesday, 28 Dec 2010
06:34 remko search for other commits by this committer
Add Drupal views plugin - Cross Site Scripting (XSS).

While here, improve previously added vuln entry by
following style a bit better.

PR:             153474
Submitted by:   rea
Original commit
Thursday, 23 Dec 2010
14:12 decke search for other commits by this committer
- Document redmine -- multiple vulnerabilities
Original commit
Wednesday, 22 Dec 2010
16:10 remko search for other commits by this committer
Add Tor remote crash and the possibility of remote code execution.

Submitted by:   Janne Snabb <snabb at epipe dot com>
Original commit
Thursday, 16 Dec 2010
18:11 delphij search for other commits by this committer
Update to properly cover php52.

Noticed by:     Chris St Denis <chris smartt com>
Original commit
Wednesday, 15 Dec 2010
23:48 glarkin search for other commits by this committer
- Document JavaScript injection exploits in Yahoo UI (YUI) library
Original commit
Monday, 13 Dec 2010
23:44 delphij search for other commits by this committer
Document PHP multiple vulnerabilities
Original commit
Friday, 10 Dec 2010
11:48 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
01:02 stas search for other commits by this committer
- Document recent MIT krb5 checksum handling vulnerabilities.
Original commit
Tuesday, 7 Dec 2010
18:02 rene search for other commits by this committer
Document the known vulnerabilities for www/chromium.

The [numbers] in the entry represent bug numbers which are clickable at
the referenced site, but most of them give a 403.
Original commit
Saturday, 4 Dec 2010
04:29 osa search for other commits by this committer
Document ProFTPD compromised source packages backdoor security issue.
Original commit
Tuesday, 30 Nov 2010
03:00 sunpoet search for other commits by this committer
- Document phpMyAdmin XSS attack in database search
Original commit
Wednesday, 24 Nov 2010
18:27 wxs search for other commits by this committer
Document net/isc-dhcp41-server DHCPv6 DoS. The update to the port is coming
shortly.
Original commit
06:07 danfe search for other commits by this committer
Add entry for CVE-2010-4168: denial of service (server/client) via invalid
read in OpenTTD.

PR:             ports/152529
Submitted by:   kwm
Original commit
04:54 danfe search for other commits by this committer
- Kill EOL whitespace and reformat to fit in standard terminal width better
- Clean up the way <p>...</p> tags are used throughout the file for consistency
Original commit
Tuesday, 23 Nov 2010
19:02 thierry search for other commits by this committer
Add an entry for www/horde-base VCARD attachments XSS vulnerability.

Security:       VuXML: a3314314-f731-11df-a757-0011098ad87f
Original commit
17:42 simon search for other commits by this committer
Fix discovery date in last entry.

Pointy hat to:  remko
Original commit
16:38 remko search for other commits by this committer
Add proftpd remote root vulnerability.

Based on:       Vladimir Nikolic <vladimir dot nikolic at amis dot net>
Feature proof:  yes
With hat:       secteam
Original commit
Wednesday, 17 Nov 2010
11:09 dinoex search for other commits by this committer
- add security/openssl CVE-2010-3864
Original commit
Saturday, 6 Nov 2010
17:55 nox search for other commits by this committer
- Update to 10.1r102 resp. 9.0r289.
- Drop MD5 hashes from distinfos

Security:      
http://www.freebsd.org/ports/portaudit/76b597e4-e9c6-11df-9e10-001b2134ef46.html
Reported by:    Matthias Apitz on -emulation
Original commit
04:08 delphij search for other commits by this committer
Add wireshark CVE-2010-3445.

PR:             ports/151891
Submitted by:   Eygene Ryabinkin
Original commit
Thursday, 4 Nov 2010
01:50 sunpoet search for other commits by this committer
- Limit affected version of dovecot to 1.2.* before 1.2.8
  (vid: 30211c45-e52a-11de-b5cd-00e0815b8da8)

Reported by:    Adam McDougall <mcdouga9@egr.msu.edu>
Reference:     
http://www.dovecot.org/list/dovecot-news/2009-November/000143.html
Original commit
Wednesday, 3 Nov 2010
20:29 wxs search for other commits by this committer
Document mailman XSS.

PR:             ports/151918
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
15:45 skv search for other commits by this committer
Document "otrs" - multiple XSS and denial of service vulnerabilities.
Original commit
Thursday, 28 Oct 2010
09:17 beat search for other commits by this committer
- Document mozilla -- Heap buffer overflow mixing document.write and DOM
  insertion
Original commit
Tuesday, 26 Oct 2010
16:46 dinoex search for other commits by this committer
- www/opera
PR:             151471
Submitted by:   Arjan van Leeuwen
Original commit
Monday, 25 Oct 2010
16:03 sunpoet search for other commits by this committer
- Add bzip2 integer overflow vulnerability

Approved by:    pgollucci (mentor, implicit)
Original commit
14:58 wxs search for other commits by this committer
Add the missing FreeBSD SA entries. We used to add these but stopped a while
back. This should catch us up.

According to cperciva@ the reason we stopped was that it was causing a lot of
false positives. I ran portaudit with these changes and did not see any false
positives but if it turns out to be too noisy I will remove them.

Submitted by:   Christopher J. Umina (private mail)
Approved by:    cperciva@
Original commit
Sunday, 24 Oct 2010
17:08 rene search for other commits by this committer
Add monotone denial of service.

Security:       http://www.monotone.ca/NEWS
Original commit
Wednesday, 20 Oct 2010
21:13 pgollucci search for other commits by this committer
- Add devel/apr0 to list of packages that is affect.
Original commit
15:12 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
12:42 kwm search for other commits by this committer
Add multiple vulnabilities in webkit-gtk2.
Original commit
Wednesday, 6 Oct 2010
05:44 pgollucci search for other commits by this committer
- set modified date
Original commit
05:41 pgollucci search for other commits by this committer
- these 2 urls are covered by the <cvename/> tags

Suggested by:   stas
Original commit
05:36 pgollucci search for other commits by this committer
- Fix a minor typo

Reported by:    stas
Original commit
05:29 pgollucci search for other commits by this committer
Document devel/apr1's apr-util vunerabilities

Security:       http://secunia.com/advisories/41701
Reviewed by:    secteam (cperciva) via irc
Original commit
Saturday, 2 Oct 2010
11:16 niels search for other commits by this committer
Documented phpMyFaq XSS vulnerability

PR:             ports/151055
Submitted by:   Florian Smeets <flo@smeets.im>
Approved by:    itetcu (mentor, implicit)
Security:       http://www.phpmyfaq.de/advisory_2010-09-28.php
Original commit
Tuesday, 28 Sep 2010
18:04 thierry search for other commits by this committer
Report an XSS vulnerability in ftp/horde-gollem.
Original commit
17:48 thierry search for other commits by this committer
Report a XSS vulnerability in mail/horde-dimp.
Original commit
17:30 thierry search for other commits by this committer
Report a XSS vulnerability in mail/horde-imp.
Original commit
17:09 thierry search for other commits by this committer
Report 2 vulnerabilities in www/horde-base.
Original commit
Sunday, 26 Sep 2010
13:32 niels search for other commits by this committer
Documented remote code execution vulnerability in OpenX

PR:             ports/150610
Approved by:    itetcu (mentor, implicit)
Security:       ttp://blog.openx.org/09/security-update/
Original commit
Friday, 24 Sep 2010
20:24 niels search for other commits by this committer
Documented squid denial of service vulnerability

PR:             ports/150364
Submitted by:   Thomas-Martin Seck <tmseck@web.de>
Approved by:    itetcu (mentor, implicit)
Security:       CVE-2010-3072
Security:       http://www.squid-cache.org/Advisories/SQUID-2010_3.txt
Original commit
Wednesday, 22 Sep 2010
17:45 nox search for other commits by this committer
Update to 10.1r85 resp. 9.0r283 [1].

Security:      
http://www.freebsd.org/ports/portaudit/8a34d9e6-c662-11df-b2e1-001b2134ef46.html
PR:             ports/150832 [2]
Submitted by:   pointyhat via pav [1], Tsurutani Naoki
                <turutani@scphys.kyoto-u.ac.jp> [2]
Original commit
Friday, 17 Sep 2010
20:07 delphij search for other commits by this committer
Correct discovery date, my bad :(
Original commit
19:31 delphij search for other commits by this committer
Document django XSS vulnerability.
Original commit
Wednesday, 15 Sep 2010
15:37 decke search for other commits by this committer
- Add libxul as affected package to the latest mozilla entry

Approved by:    beat (co-mentor)
Original commit
Friday, 10 Sep 2010
13:41 jadawin search for other commits by this committer
- Fix CVE name for webkit-gtk2
Original commit
13:03 kwm search for other commits by this committer
Document webkit-gtk2 - multiple vulnerabilities.

Also add 1 extra CVE to the previous webkit-gtk2 entry that was fixed but
didn't make it to the release notes.
Original commit
Thursday, 9 Sep 2010
03:13 shaun search for other commits by this committer
Belatedly (and perhaps pointlessly) document [1]:

  vim6 -- heap-based overflow while parsing shell metacharacters

While here, prepare this old port for termination with DEPRECATED.

PR:             ports/129300 [1]
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru> [1]
Original commit
Wednesday, 8 Sep 2010
06:51 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
Tuesday, 7 Sep 2010
18:11 wxs search for other commits by this committer
Document sudo Runas group vulnerability.
Original commit
Saturday, 4 Sep 2010
16:20 bapt search for other commits by this committer
- wget 1.12_1 is also concerned
Original commit
Friday, 3 Sep 2010
13:57 bapt search for other commits by this committer
- Add wget entry CVE-2010-2252
- Add lftp entry CVE-2010-2251
Original commit
Tuesday, 31 Aug 2010
14:53 jadawin search for other commits by this committer
 - Document p5-libwww vulnerability (remote servers can create .(dot) files)
Original commit
Wednesday, 25 Aug 2010
07:49 niels search for other commits by this committer
Documented quagga vulnerabilities (stack overflow, DoS)

Approved by:    itetcu (mentor,implicit)
Security:       http://www.openwall.com/lists/oss-security/2010/08/24/3
Security:       http://www.quagga.net/news2.php?y=2010&m=8&d=19#id1282241100
Original commit
Tuesday, 24 Aug 2010
16:26 skv search for other commits by this committer
Document "bugzilla" - information disclosure, denial of service.
Original commit
Monday, 23 Aug 2010
07:12 lwhsu search for other commits by this committer
- Fix version range of phpMyAdmin

Submitted by:   Marko Njezic <mr.max AT maxempire.com>
Original commit
Sunday, 22 Aug 2010
17:19 danfe search for other commits by this committer
Adjust the version range in previous entry: 1.0.1 is also vulnerable, and
fix minor whitespace nit while here.
Original commit
12:30 kwm search for other commits by this committer
Add entry for OpenTTD denial of server vulnability.

Reviewed by:    danfe@ (OpenTTD maintainer)
Original commit
Saturday, 21 Aug 2010
21:30 niels search for other commits by this committer
- Added corkscrew: overflow condition due to insecure sscanf usage
- Fixed SLiM title: /SLiM/slim/

Approved by:    itetcu (mentor, implicit)
Security:       http://people.freebsd.org/~niels/issues/corkscrew-20100821.txt
Original commit
12:42 lwhsu search for other commits by this committer
- Add phpMyAdmin's CVE-2010-3056 entry
Original commit
Friday, 20 Aug 2010
23:34 stas search for other commits by this committer
- Fix date of the latest ruby entry.
Original commit
21:00 niels search for other commits by this committer
Added CVE to SLiM vulnerability

Approved by:    itetcu (mentor, implicit)
Security:       CVE-2010-2945
Original commit
Thursday, 19 Aug 2010
21:11 niels search for other commits by this committer
- Document SLiM insecure PATH assignment issue
- Removed space from vlc title

Approved by:    itetcu (implicit, mentor)
Security:       http://seclists.org/oss-sec/2010/q3/198
Original commit
Wednesday, 18 Aug 2010
06:36 stas search for other commits by this committer
- Document recent WEBrick XSS vulnerability in ruby.
Original commit
Tuesday, 17 Aug 2010
12:50 bapt search for other commits by this committer
- Add security/isolate entry

PR:             ports/148911
Submitted by:   Steve Wills <steve _at_ mouf.net> (maintainer)
Approved by:    tabthorpe (mentor)
Original commit
Sunday, 15 Aug 2010
17:10 shaun search for other commits by this committer
Fix krb5 entry (86b8b655-4d1a-11df-83fb-0015587e2cc1) version range
mark-up.

Submitted by:   Peggy Wilkins via freebsd-ports
Original commit
Saturday, 14 Aug 2010
22:43 gabor search for other commits by this committer
- Fix last entry by adding the forgotten package name.
  (Hint: always run make validate before committing to this file)

Forgotten by:   jsa, kwm
Original commit
20:51 jsa search for other commits by this committer
Document VLC CVE-2010-2937.

Approved by:    kwm (mentor)
Original commit
Friday, 13 Aug 2010
20:15 nox search for other commits by this committer
Update to 10.1r82 resp. 9.0r280.

Security:      
http://www.freebsd.org/ports/portaudit/e19e74a4-a712-11df-b234-001b2134ef46.html
Original commit
15:23 shaun search for other commits by this committer
Document opera -- multiple vulnerabilities.
Original commit
Monday, 9 Aug 2010
09:10 beat search for other commits by this committer
- Belatedly document firefox -- Dangling pointer crash regression from plugin
  parameter array fix

Approved by:    miwi
Original commit
Wednesday, 4 Aug 2010
14:47 wxs search for other commits by this committer
Whitespace fixes.
Original commit
09:32 lwhsu search for other commits by this committer
- Fix Piwik entry's <name> tag

Pointed out by: jadawin
Original commit
09:18 lwhsu search for other commits by this committer
- Add Piwik CVE-2010-2786 entry
Original commit
Saturday, 31 Jul 2010
12:00 kuriyama search for other commits by this committer
Previous vuln affects only apache-2.2.x
Original commit
Thursday, 29 Jul 2010
23:03 gabor search for other commits by this committer
- Document libmspack and cabextract vulnerability
Original commit
Monday, 26 Jul 2010
01:42 kuriyama search for other commits by this committer
Add entry for apache.
Original commit
Friday, 23 Jul 2010
00:37 wxs search for other commits by this committer
Document buffer overflow when parsing gitdir.
While here, tidy up a whitespace problem.
Original commit
Wednesday, 21 Jul 2010
22:25 glarkin search for other commits by this committer
- Document www/codeigniter file upload class vulnerability

Approved by:    secteam (timeout - 1 week)
Security:       http://codeigniter.com/news/codeigniter_1.7.2_security_patch/
Original commit
12:46 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities

Approved by:    remko
Original commit
Monday, 19 Jul 2010
00:07 kwm search for other commits by this committer
Add vte as package name, instead of empty.
Original commit
Sunday, 18 Jul 2010
23:28 kwm search for other commits by this committer
Document vte title set+query attack vulnerability.

While here add the CVE numbers to the webkit-gtk2 entry I forgot in the
previous commit.

PR:             ports/148678
Submitted by:   Janne Snabb <snabb@epipe.com>
Original commit
22:44 kwm search for other commits by this committer
Document webkit-gtk2 vulnerabilities.

Security:       http://blog.kov.eti.br/?p=116
Original commit
Saturday, 10 Jul 2010
08:34 decke search for other commits by this committer
- Document redmine vulnerabilities

Approved by:    miwi (secteam)
Security:       http://www.redmine.org/news/41
Original commit
Wednesday, 7 Jul 2010
09:13 nemoliu search for other commits by this committer
- Update to 3.1.1
- VuXML entry for PNG decoder security vulnerability
- License information

PR:     ports/147871
Approved by:    Pavel Pankov <pankov_p@mail.ru> (maintainer)
Feature safe:   yes
Original commit
Tuesday, 6 Jul 2010
21:39 delphij search for other commits by this committer
Add bogofilter heap underrun on malformed base64 input.

Submitted by:   mandree
PR:             ports/148408
Feature safe:   yes
Original commit
04:38 miwi search for other commits by this committer
- Cleanup a bit

Feature safe:   yes
Original commit
Monday, 5 Jul 2010
15:41 skv search for other commits by this committer
Document "bugzilla" - information disclosure.

Feature safe:   yes
Original commit
Wednesday, 30 Jun 2010
21:00 makc search for other commits by this committer
Document multiple vulnerabilities in irc/kvirc*

Approved by:    remko@
Feature safe:   yes
Original commit
Monday, 28 Jun 2010
17:38 delphij search for other commits by this committer
Add bid reference for libpng entry.

Feature safe:   yes
Original commit
16:18 dinoex search for other commits by this committer
- graphics/png CVE-2010-1205
Feature safe:   yes
Original commit
00:46 wen search for other commits by this committer
- Document moodle -- multiple vulnerabilities

Reviewed by:    delphij@, miwi@
Feature safe:   yes
Original commit
Sunday, 27 Jun 2010
21:14 rene search for other commits by this committer
Document mDNSResponder -- corrupted stack crash when parsing bad resolv.conf

This only happens on a system where one has a system where
resolv.conf is writable by an untrusted user or where mdnsd is setuid
and can be tricked into opening an alternate resolv.conf.
PR:             ports/147007
Submitted by:   jmallett@
Approved by:    tabthorpe (mentor)
Feature safe:   yes
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46  »  [Last Page]