notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47  »  [Last Page]

Friday, 25 Jun 2010
23:29 shaun search for other commits by this committer
Document opera -- Data URIs can be used to allow cross-site scripting.

Assume opera-devel is vulnerable too, although snapshots aren't
mentioned in the advisory, and it's months out of date.

Feature safe:   yes
Original commit
Thursday, 24 Jun 2010
12:54 niels search for other commits by this committer
- Cancelled movemail symlink vulnerability (doesnt affect our ports)
- Added entry for multiple vulnerabilities in cacti 0.8.7f
- Updated ziproxy entry to satisfy "make tidy"

Approved by:    itetcu (mentor, implicit)
Feature safe:   yes
Original commit
Wednesday, 23 Jun 2010
18:01 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities

Feature safe:   yes
Approved by:    delphij
Original commit
Friday, 18 Jun 2010
00:38 delphij search for other commits by this committer
vuln 4e8344a3-ca52-11de-8ee8-00215c6a37bb has been fixed with
php4-gd-4.4.9_4.

Requested by:   Michael Gmelin <mg bindone de>
Original commit
Wednesday, 16 Jun 2010
12:42 erwin search for other commits by this committer
Fix typo in previous revision.
Original commit
12:13 miwi search for other commits by this committer
- Cleanup, Formating
Original commit
09:31 dinoex search for other commits by this committer
add CVE-2009-2347 tiff
Original commit
Tuesday, 15 Jun 2010
19:46 nox search for other commits by this committer
Document linux-flashplugin -- multiple vulnerabilities.

Reviewed by:    tmclaugh
Original commit
Monday, 14 Jun 2010
03:04 miwi search for other commits by this committer
- Cleanup / Whitespace fixes
Original commit
Saturday, 12 Jun 2010
17:22 erwin search for other commits by this committer
Remove empty package in previous revision.
Original commit
16:44 dinoex search for other commits by this committer
- report FAX3 decoder buffer overrun
Original commit
Thursday, 3 Jun 2010
00:10 wxs search for other commits by this committer
Document sudo secure path vulnerability. We are not vulnerable to this by
default but a user could build sudo with SUDO_SECURE_PATH defined or turn
it on in sudoers.
Original commit
Wednesday, 2 Jun 2010
11:24 pav search for other commits by this committer
- Update to 3.0.1

PR:             ports/147195
Submitted by:   Pavel Pankov <pankov_p@mail.ru> (maintainer)
Original commit
06:20 wen search for other commits by this committer
- Document two mediawiki security vulnerabilities

Approved by:    delphij@(ports-security override)
Original commit
Friday, 14 May 2010
18:28 decke search for other commits by this committer
- Document multiple redmine vulnerabilities

Approved by:    miwi (secteam), beat (co-mentor)
Security:       http://www.redmine.org/news/39
Original commit
Thursday, 13 May 2010
09:12 niels search for other commits by this committer
Updated tomcat entry (CVE-2010-1157) with fixed version information.
This makes sure that the correct older versions are marked vulnerable

Approved by:    itetcu (mentor, implicit)
Security:      
http://www.vuxml.org/freebsd/3383e706-4fc3-11df-83fb-0015587e2cc1.html
Original commit
Wednesday, 12 May 2010
09:46 niels search for other commits by this committer
- Added 109 missing CVE names to 60 VuXML entries
- Fixed Tomcat55 entry to mark current PORTREVISION vulnerable

PR:             ports/146418
Approved by:    itetcu (mentor, implicit)
Security:       http://people.freebsd.org/~niels/vuxml/
Original commit
Friday, 7 May 2010
19:53 niels search for other commits by this committer
Added wireshark (DoS) and piwik (XSS) issues

Approved by:    itetcu (mentor, implicit)
Security:       http://www.wireshark.org/security/wnpa-sec-2010-03.html
Security:       http://www.wireshark.org/security/wnpa-sec-2010-04.html
Security:       http://piwik.org/blog/2010/04/piwik-0-6-security-advisory/
Original commit
Thursday, 6 May 2010
19:44 niels search for other commits by this committer
Added spamass-milter remote command execution vulnerability

Approved by:    itetcu (mentor, implicit)
Security:       CVE-2010-1132
Security:      
http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html
Original commit
Wednesday, 5 May 2010
19:12 niels search for other commits by this committer
- Added mediawiki and lxr vulnerabilities
- Fixed vlc topic format (lower case, portname first)

PR:             ports/146337
Approved by:    itetcu (mentor, implicit)
Security:      
http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-April/000090.html
Security:      
http://sourceforge.net/mailarchive/message.php?msg_name=E1NS2s4-0001PE-F2%403bkjzd1.ch3.sourceforge.com
Original commit
Tuesday, 4 May 2010
20:46 niels search for other commits by this committer
Added 38 missing CVE names to 24 VuXML entries
(256 CVE names to go)

Approved by:    itetcu (mentor, implicit)
Security:       http://people.freebsd.org/~niels/vuxml/
Original commit
Sunday, 2 May 2010
15:32 niels search for other commits by this committer
Added 34 missing CVE names to 24 VuXML entries
(294 CVE names to go)

Approved by:    miwi (secteam)
Security:       http://people.freebsd.org/~niels/vuxml/
Original commit
00:52 sylvio search for other commits by this committer
- VideoLAN has released 1.0.6 to address serveral vulnerabilities they discoverd
while working towards the 1.1.0 release. These vulnerabilities could potentially
allow for a specially crafted file to execute code.

PR:             ports/146099
Submitted by:   Joseph S. Atkinson <jsa@wickedmachine.net> (maintainer)
Original commit
Friday, 30 Apr 2010
04:25 dinoex search for other commits by this committer
- fix version for apache+mod_ssl
Original commit
04:24 dinoex search for other commits by this committer
- fix info for apache+mod_ssl
Original commit
Wednesday, 28 Apr 2010
21:09 makc search for other commits by this committer
Mark kdebase3 as safe now.
Original commit
Tuesday, 27 Apr 2010
05:46 niels search for other commits by this committer
- Documented multiple Joomla! vulnerabilities
- Added new reference to the recent cacti issue

Approved by:    remko (secteam)
Security:       http://developer.joomla.org/security/
Original commit
Saturday, 24 Apr 2010
21:14 niels search for other commits by this committer
Documented vulnerabilities in moodle, tomcat55, tomcat66 and cacti

PR:             ports/146021
PR:             ports/146022
Approved by:    remko (secteam)
Security:       http://seclists.org/bugtraq/2010/Apr/200
Security:       http://docs.moodle.org/en/Moodle_1.9.8_release_notes
Security:       http://www.bonsai-sec.com/en/research/vulnerability.php
Original commit
Friday, 23 Apr 2010
18:16 niels search for other commits by this committer
Documented emacs movemail vulnerability and marked the seperate
mail/movemail port vulnerable to an old format string vulnerability.

Approved by:    remko (secteam)
Security:       http://www.ubuntu.com/usn/USN-919-1
Original commit
Wednesday, 21 Apr 2010
20:19 niels search for other commits by this committer
Added krb5 double free vulnerability

Approved by:    remko (secteam)
Security:       http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-004.txt
Security:       CVE-2010-1320
Original commit
Tuesday, 20 Apr 2010
21:03 niels search for other commits by this committer
Documented the following vulnerabilities:
- png: libpng decompression denial of service
- e107: code execution and XSS vulnerabilities
- pidgin: multiple remote denial of service vulnerabilities
- fetchmail: denial of service vulnerability

PR:             ports/145885
PR:             ports/145857
Approved by:    remko (secteam)
Security:       CVE-2010-0996
Security:       CVE-2010-0997
Security:       CVE-2010-1167
Security:       CVE-2010-0277
Security:       CVE-2010-0420
Security:       CVE-2010-0423
Security:       CVE-2010-0205
Original commit
Monday, 19 Apr 2010
19:06 niels search for other commits by this committer
Documented the following vulnerabilities:
- curl: libcurl buffer overflow vulnerability
- irssi: multiple vulnerabilities
- ejabberd: queue overload denial of service vulnerability

Approved by:    remko (secteam)
Security:       http://curl.haxx.se/docs/adv_20100209.html
Security:       http://support.process-one.net/browse/EJAB-1173
Security:       http://xforce.iss.net/xforce/xfdb/57790
Security:       http://xforce.iss.net/xforce/xfdb/57791
Original commit
07:13 niels search for other commits by this committer
- Added three krb5 vulnerabilities
- Fixed indent on mahara entry
- Fixed title of KDM entry

Approved by:    remko (secteam)
Security:       http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-001.txt
Security:       http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-002.txt
Security:       http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-003.txt
Original commit
Sunday, 18 Apr 2010
19:00 niels search for other commits by this committer
Document mahara sql injection vulnerability

Approved by:    remko (secteam)
Security:       http://www.debian.org/security/2010/dsa-2030
Original commit
Friday, 16 Apr 2010
02:25 wxs search for other commits by this committer
Correct CVE entry. The advisory from Todd[0] says CVE 2010-0426, which is
the entry assigned to the original sudoedit vulnerability[1]. The new
one (CVE-2010-1163) was just assigned. I believe the one assigned by CVE
folks is the proper one to use.

[0]: http://sudo.ws/sudo/alerts/sudoedit_escalate2.html
[1]: 018a84d0-2548-11df-b4a3-00e0815b8da8
Original commit
Thursday, 15 Apr 2010
20:53 wxs search for other commits by this committer
- Document sudo privilege escalation bug. This is similar to
  018a84d0-2548-11df-b4a3-00e0815b8da8.
Original commit
Wednesday, 14 Apr 2010
21:46 avilla search for other commits by this committer
- Do not match x11/kdebase4 in latest KDM vulnerability.

Approved by:    tabthorpe (mentor)
Original commit
19:04 avilla search for other commits by this committer
- Document KDM local privilege escalation vulnerability.

Approved by:    tabthorpe (mentor), delphij (secteam)
Original commit
Tuesday, 6 Apr 2010
17:53 glarkin search for other commits by this committer
- Document dojo - cross-site scripting and other vulnerabilities
- Document ZendFramework - security issues in bundled Dojo library

Approved by:    secteam (remko)
Security:      
http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory/
Security:       http://framework.zend.com/security/advisory/ZF2010-07
Original commit
07:36 beat search for other commits by this committer
- Document firefox -- Re-use of freed object due to scope confusion

Submitted by:   Florian Smeets <flo AT smeets.im>
Approved by:    miwi
Original commit
Tuesday, 30 Mar 2010
22:25 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities

Approved by:    delphij
Original commit
Thursday, 25 Mar 2010
21:45 delphij search for other commits by this committer
Document postgresql bitsubstr overflow vulnerability
Original commit
Wednesday, 24 Mar 2010
18:48 naddy search for other commits by this committer
Document a buffer overflow in gtar's rmt client functionality.
Original commit
Tuesday, 23 Mar 2010
08:36 beat search for other commits by this committer
- Document firefox -- WOFF heap corruption due to integer overflow

Approved by:    miwi
Original commit
Monday, 22 Mar 2010
21:31 niels search for other commits by this committer
Updated the xzgv entry: 0.9 version (now in portstree) is not vulnerable

Approved by:    itetcu (mentor), miwi (secteam)
Security:      
http://www.vuxml.org/freebsd/a813a219-d2d4-11da-a672-000e0c2e438a.html
Security:       http://www.gentoo.org/security/en/glsa/glsa-200604-10.xml
Original commit
Friday, 19 Mar 2010
10:16 miwi search for other commits by this committer
- Fix build
Original commit
07:39 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
- Fix a typo

Approved by:    miwi
Original commit
Friday, 12 Mar 2010
01:45 delphij search for other commits by this committer
Document eGroupware vulnerabilities.

Submitted by:   wenheping
Original commit
Monday, 8 Mar 2010
22:50 miwi search for other commits by this committer
- Document drupal -- multiple vulnerabilities

Feature safe:   yep
Original commit
Monday, 1 Mar 2010
17:47 wxs search for other commits by this committer
- Document sudo privilege escalation vulnerability when using
  pseudo-command sudoedit

Feature safe:   yes
Original commit
Sunday, 28 Feb 2010
20:25 nox search for other commits by this committer
Attempt to properly take care of the ooo3 -RC and -devel ports too (doh!)

Feature safe:   yes
Original commit
13:07 beat search for other commits by this committer
- Document thunderbird3 vulnerabilities

Approved by:    miwi
Feature safe:   yes
Original commit
Friday, 26 Feb 2010
21:20 nox search for other commits by this committer
Document openoffice -- multiple vulnerabilities

Reviewed by:    delphij
Feature safe:   yes
Original commit
Thursday, 18 Feb 2010
10:02 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities

Approved by:    miwi (secteam)
Feature safe:   yes
Original commit
Tuesday, 16 Feb 2010
18:06 delphij search for other commits by this committer
Document lighttpd remote DoS vulnerability.

Reported by:    Dan Rowe <dan dracosplace com>
Feature safe:   yes
Original commit
Monday, 15 Feb 2010
06:29 delphij search for other commits by this committer
Update www/squid and www/squid30 to address Squid HTCP Packet Processing
NULL Pointer Dereference vulnerability (SQUID-2010:2)
Original commit
Saturday, 13 Feb 2010
21:55 nox search for other commits by this committer
Document linux-flashplugin -- multiple vulnerabilities.

Reviewed by:    miwi
Original commit
10:29 kwm search for other commits by this committer
Add CVE-2010-0414 and CVE-2010-0422 for gnome-screensaver.

Reviewed by:    miwi@
Original commit
Friday, 12 Feb 2010
14:25 mandree search for other commits by this committer
Fix range for fetchmail CVE-2010-0562.

Approved by: miwi@ (mentor)
Original commit
09:56 mandree search for other commits by this committer
Add CVE-2010-0562 entry for mail/fetchmail.

Approved by: miwi (mentor).
Original commit
Wednesday, 10 Feb 2010
00:47 delphij search for other commits by this committer
Document wireshark lwres buffer overflow vulnerability.

Reported by:    Andreas <akoga hawaii edu>
Original commit
Monday, 8 Feb 2010
16:38 skv search for other commits by this committer
Document "otrs" - SQL injection.
Original commit
Wednesday, 3 Feb 2010
23:25 pgollucci search for other commits by this committer
- add the rest of the apache 1.3.x packages to the list
  that are vulnerable
- add a missing ) to the <topic>

Reviewed by:    secteam (miwi)
Original commit
22:24 pgollucci search for other commits by this committer
- document chunk-size integer overflow in apache 1.3.x
Original commit
21:47 pgollucci search for other commits by this committer
- remove extraneou '>' as reported by make tidy
Original commit
Tuesday, 2 Feb 2010
22:42 miwi search for other commits by this committer
- Mark squid30 now as safe
Original commit
09:44 miwi search for other commits by this committer
- Update 296ecb59-0f6b-11df-8bab-0019996bc1f7 entry and makr squid3* as safe
Original commit
Monday, 1 Feb 2010
20:25 delphij search for other commits by this committer
Security patch for Squid advisory 2010:1, denial of service.

Submitted by:   maintainer (Thomas-Martin Seck <tmseck web de>)
Original commit
16:45 skv search for other commits by this committer
Document "bugzilla" - information leak.
Original commit
Thursday, 28 Jan 2010
21:20 miwi search for other commits by this committer
- Correct fixed version from previous entry
Original commit
21:15 miwi search for other commits by this committer
- Document irc-ratbox -- multiple vulnerabilities

PR:             based on 143242
Submitted by:   moggie <moggie@elasticmind.net>
Original commit
Thursday, 21 Jan 2010
19:52 beat search for other commits by this committer
- Document thunderbird3 vulnerabilities

Reviewed by:    miwi
Original commit
Monday, 18 Jan 2010
17:45 delphij search for other commits by this committer
Document dokuwiki multiple vulnerabilities.
Original commit
Thursday, 14 Jan 2010
03:32 glarkin search for other commits by this committer
- Added entry for multiple vulnerabilities in www/zend-framework
- Cleaned up some entries reported by "make tidy"

Reviewed by:    secteam (delphij via email)
Approved by:    secteam (delphij via email)
Security:       http://framework.zend.com/security/advisory/ZF2010-06
Security:       http://framework.zend.com/security/advisory/ZF2010-05
Security:       http://framework.zend.com/security/advisory/ZF2010-04
Security:       http://framework.zend.com/security/advisory/ZF2010-03
Security:       http://framework.zend.com/security/advisory/ZF2010-02
Security:       http://framework.zend.com/security/advisory/ZF2010-01
Security:       http://framework.zend.com/security/advisory/ZF2009-02
Security:       http://framework.zend.com/security/advisory/ZF2009-01
Original commit
Saturday, 9 Jan 2010
10:55 delphij search for other commits by this committer
Document powerdns-recursor multiple vulnerabilities.
Original commit
Monday, 4 Jan 2010
23:23 delphij search for other commits by this committer
Document pear-Net_Ping and pear-Net_Traceroute arbitrary command execution
vulnerability.
Original commit
Saturday, 2 Jan 2010
16:29 erwin search for other commits by this committer
Bump copyright year to 2010
Original commit
Friday, 25 Dec 2009
19:19 miwi search for other commits by this committer
- Document drupal -- multiple cross-site scripting
Original commit
Monday, 21 Dec 2009
21:48 stas search for other commits by this committer
- Document sysutils/fuser privileges check vulnerability.
Original commit
18:19 delphij search for other commits by this committer
Document monkey remote DoS vulnerability.
Original commit
10:45 miwi search for other commits by this committer
- Fix a typo (s/opensll/openssl)

Reported by:    pluknet <pluknet@gmail.com>
Original commit
Thursday, 17 Dec 2009
22:40 delphij search for other commits by this committer
Document php multiple vulnerabilities.

Sponsored by:   iXsystems, Inc.
Original commit
00:24 delphij search for other commits by this committer
Document PostgreSQL multiple vulnerabilities.

Sponsored by:   iXsystems, Inc.
Original commit
00:04 delphij search for other commits by this committer
Add tptest pwd remote buffer overflow vulnerability.

Submitted by:   Mark Foster <mark foster cc>
PR:             ports/131938
Original commit
Wednesday, 16 Dec 2009
10:44 miwi search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
Tuesday, 15 Dec 2009
02:27 delphij search for other commits by this committer
Make the problem more visible by choosing a more descriptive subject.
Original commit
00:39 delphij search for other commits by this committer
Document freeradius remote packet of death exploit (CVE 2009-3111)

Submitted by:   "Danilo G. Baio" <dbaio bs2 com br>
PR:             ports/141318
Original commit
Monday, 14 Dec 2009
16:12 beat search for other commits by this committer
- Mark Seamonkey 2.0 as safe

Reviewed by:    miwi
Original commit
Saturday, 12 Dec 2009
18:12 beat search for other commits by this committer
- Mark linux-firefox-devel as safe

Reviewed by:    miwi
Original commit
11:08 miwi search for other commits by this committer
- Fix build
Original commit
10:58 wen search for other commits by this committer
- Document pligg -- Cross-Site Scripting and Cross-Site Request Forgery
Original commit
Friday, 11 Dec 2009
15:27 miwi search for other commits by this committer
- Document piwik -- php code execution

Requested by:   wen
Original commit
15:14 miwi search for other commits by this committer
- Fix previous entrys (formating etc)
Original commit
Thursday, 10 Dec 2009
15:27 wxs search for other commits by this committer
- Document dovecot insecure directory permissions
Original commit
00:32 nox search for other commits by this committer
Document linux-flashplugin -- multiple vulnerabilities.

Reviewed by:    miwi
Original commit
Wednesday, 9 Dec 2009
23:39 stas search for other commits by this committer
- Document ruby 1.9.1 heap overflow vulnerability.
Original commit
15:07 skreuzer search for other commits by this committer
Document session fixation vulnerability in RequestTracker < 3.8.6

Reviewed by:    simon@, wxs@
Original commit
Tuesday, 8 Dec 2009
01:44 kuriyama search for other commits by this committer
- Add two CVE entries for expat2.
Original commit
Tuesday, 1 Dec 2009
20:09 miwi search for other commits by this committer
- Document opera -- multiple vulnerabilities

Request by:     itetcu
Original commit
Saturday, 28 Nov 2009
22:48 kwm search for other commits by this committer
Fix the libtool entry to include 2.2.6a as vulnerable.
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47  »  [Last Page]