notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48  »  [Last Page]

Saturday, 28 Nov 2009
21:03 kwm search for other commits by this committer
Document libtool vulnerability.

Reviewed by:    miwi@
Original commit
Thursday, 26 Nov 2009
14:51 miwi search for other commits by this committer
- Cleanup (whitespaces/tabs)
Original commit
Tuesday, 24 Nov 2009
21:34 naddy search for other commits by this committer
document: libvorbis -- multiple vulnerabilities
Original commit
Monday, 23 Nov 2009
18:07 skv search for other commits by this committer
Document "bugzilla" - information leak.
Original commit
15:47 sem search for other commits by this committer
- Report a XSS vulnerability in net-mgmt/cacti port
Original commit
Saturday, 14 Nov 2009
12:41 miwi search for other commits by this committer
- fix german wordpress name
Original commit
12:20 miwi search for other commits by this committer
- Document wordpress -- multiple vulnerabilities
Original commit
Monday, 9 Nov 2009
17:14 delphij search for other commits by this committer
Mark php5-gd 5.2.11_2 as safe.
Original commit
Sunday, 8 Nov 2009
23:33 wxs search for other commits by this committer
- Note that CVE-2009-3546 has been fixed in graphics/gd.

Noticed by:     N.J. Mann <njm@njm.me.uk>
Original commit
Friday, 6 Nov 2009
09:43 miwi search for other commits by this committer
- Fix previous commit
Original commit
08:22 jadawin search for other commits by this committer
- Document HTML-Parser denial of service
Original commit
Thursday, 5 Nov 2009
21:40 delphij search for other commits by this committer
Document remote buffer overflow vulnerability in gd.
Original commit
21:25 delphij search for other commits by this committer
Document typo3 multiple vulnerabilities.

Notified by:    Wennrich, Markus <Markus Wennrich f-i-ts de>
Original commit
Tuesday, 3 Nov 2009
21:18 thierry search for other commits by this committer
Add an entry for VideoLAN-SA-0901, about multimedia/vlc.
Original commit
Monday, 2 Nov 2009
20:12 miwi search for other commits by this committer
- Document KDE -- multiple vulnerabilities

Reported by:    Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
Saturday, 31 Oct 2009
12:52 miwi search for other commits by this committer
- Fix previous entry
Original commit
12:41 itetcu search for other commits by this committer
Add two opera vulnerabilities

PR:             140101
Submitted by:   Arjan van Leeuwen
Original commit
Thursday, 29 Oct 2009
21:59 miwi search for other commits by this committer
- Fix latest entrys
Original commit
14:21 flz search for other commits by this committer
Document vulnerability in net-p2p/ctorrent < 3.3.2_2 (CVE-2009-1759).

PR:             ports/139635
Submitted by:   Eygene Ryabinkin
Security:       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1759
Original commit
Wednesday, 28 Oct 2009
23:04 stas search for other commits by this committer
- Fix linux-opera vuxml entry (it uses different version numbering scheme) [1]
- Add entry for opera-devel as well.

PR:             ports/140038 [1]
Submitted by:   Sato Kuro <poyopoyo@puripuri.plala.or.jp> [1]
Original commit
15:22 beat search for other commits by this committer
- Document mozilla -- multiple vulnerabilities

Approved by:    miwi (secteam)
Original commit
Sunday, 25 Oct 2009
14:53 gabor search for other commits by this committer
- Fix discovery date of a recent entry
Original commit
14:23 stas search for other commits by this committer
- Document elinks < 0.11.4 buffer overflow vulnerability.
Original commit
Thursday, 22 Oct 2009
23:04 delphij search for other commits by this committer
Add CVE reference provided by author via maintainer for the squidguard
issue.
Original commit
23:01 delphij search for other commits by this committer
Apply vendor fixes 20091015 and 20091019 to fix multiple vulnerabilities
of squidGuard 1.4.

Requested by:   maintainer
Security:       692ab645-bf5d-11de-849b-00151797c2d4
Original commit
Tuesday, 20 Oct 2009
11:03 araujo search for other commits by this committer
- Add an entry for Xpdf -- Multiple Vulnerabilities.
Original commit
Friday, 16 Oct 2009
17:42 lwhsu search for other commits by this committer
- Document django -- denial-of-service attack
Original commit
Tuesday, 13 Oct 2009
22:12 miwi search for other commits by this committer
- Document phpmyadmin -- XSS and SQL injection vulnerabilities
Original commit
Monday, 12 Oct 2009
17:22 wxs search for other commits by this committer
- Document php5 multiple security vulnerabilities.

PR:             ports/139196
Submitted by:   Mark Foster <mark@foster.cc>
Original commit
Wednesday, 7 Oct 2009
10:18 miwi search for other commits by this committer
- Document virtualbox -- privilege escalation
Original commit
Tuesday, 6 Oct 2009
09:37 remko search for other commits by this committer
Add FreeBSD-SA-09:14.devfs to the VuXML list.

Hat:    secteam
Facilitated by: Snow B.V.
Original commit
09:33 remko search for other commits by this committer
Add FreeBSD-SA-09:13.pipe to the VuXML list.

Hat:    secteam
Facilitated by: Snow B.V.
Original commit
Thursday, 1 Oct 2009
12:01 stas search for other commits by this committer
- linux-f10-pango is affected by 4b172278-3f46-11de-becb-001cc0377035 too.

Reported by:    "Edward Sanford Sutton, III" <mirror176@cox.net>
Original commit
Wednesday, 30 Sep 2009
15:32 miwi search for other commits by this committer
- Document mybb -- multiple vulnerabilities

PR:             based on 139197
Original commit
Tuesday, 22 Sep 2009
23:03 miwi search for other commits by this committer
- Document drupal -- Multiple Vulnerabilities

Submitted by:   Nick Hillard (based on)
Feature safe:   yes
Original commit
Monday, 21 Sep 2009
22:23 miwi search for other commits by this committer
- Rework latest horde-base entry (ee23aa09-a175-11de-96c0-0011098ad87f)

Feature safe:   yes
Original commit
Sunday, 20 Sep 2009
14:54 cy search for other commits by this committer
Fix a formatting issue.

Pointy hat to:          myself
Noticed by:             miwi
Feature safe:           Yes
Original commit
05:58 delphij search for other commits by this committer
Fix build.

Feature safe:   yes
Original commit
05:37 cy search for other commits by this committer
Document a security problem in fwbuilder/libfwbuilder 3.0.4 - 3.0.6.
Generated iptables scripts when used to generate static routing
configurations have a security issue.

Feature safe:   Yes
Original commit
Thursday, 17 Sep 2009
13:28 skv search for other commits by this committer
Document "bugzilla" - two SQL injections, sensitive data exposure.

Feature safe:   yes
Original commit
Monday, 14 Sep 2009
21:57 thierry search for other commits by this committer
Adding an entry for three vulnerabilities fixed in the latest Horde
framework (i.e. the port www/horde-base).
Original commit
20:06 stas search for other commits by this committer
- Fix formatting.
- Add link to the debian security advisory.
- Fix the description to be the actual citation from the official sources
  instead of some wild interpretation.  We do not know for sure if remote
  code execution is possible at all and from looking to the source code it
  seems unlikely as the buffer undeflown is allocated on the heap.  Moreover,
  it is not clear if this is exploitable in the default install.

Discussed with: az
Original commit
19:48 wxs search for other commits by this committer
Document nginx DoS condition.

Submitted by:   az@ (via IRC)
Original commit
Sunday, 13 Sep 2009
16:56 ume search for other commits by this committer
Add cvename and bid for cyrus-imapd potential buffer overflow
in Sieve.
Original commit
16:06 brix search for other commits by this committer
Add ikiwiki vulnerability.
Original commit
11:24 miwi search for other commits by this committer
- Cleanup previous commit
Original commit
11:06 brix search for other commits by this committer
- Add xapian-omega cross-scripting vulnerability
Original commit
Thursday, 10 Sep 2009
17:28 miwi search for other commits by this committer
- Document mozilla firefox -- Multiple Vulnerabilities
Original commit
Wednesday, 9 Sep 2009
15:13 ume search for other commits by this committer
Fix xml broke by my previous commit.
Original commit
15:08 ume search for other commits by this committer
Document cyrus-imapd potential buffer overflow vulnerability in Sieve.
Original commit
Tuesday, 8 Sep 2009
23:24 wxs search for other commits by this committer
- Document silc-toolkit format string vulnerabilities. Unfortunately little
  information is provided publicly.
Original commit
Friday, 4 Sep 2009
08:18 miwi search for other commits by this committer
- Mark seamonkey as safe
Original commit
08:02 miwi search for other commits by this committer
- Update latest Opera entry,
        * add missing linux-opera
        * fix topic
Original commit
07:26 jadawin search for other commits by this committer
- Fix vuxml build

Pointyhat to:   me
Original commit
07:12 jadawin search for other commits by this committer
- Fix vuxml build

Pointyhat to:   itetcu
Original commit
05:59 itetcu search for other commits by this committer
Add an atry for opera < 10.00

PR:             138449
Submitted by:   maintainer
Original commit
Wednesday, 2 Sep 2009
12:32 miwi search for other commits by this committer
- Fix cvenames
Original commit
11:42 miwi search for other commits by this committer
- Document dnsmasq -- TFTP server remote code injection vulnerability

PR:             138418 (based on)
Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Original commit
Tuesday, 25 Aug 2009
08:20 kuriyama search for other commits by this committer
- I cannot confirm these vulns can be affected to 1.3.x and 2.0.x
  lines.  Limit this entry to 2.2.x until confirmed.
Original commit
06:47 kuriyama search for other commits by this committer
Add apache-2.2.12 fixes.
Original commit
Saturday, 22 Aug 2009
11:48 beat search for other commits by this committer
- Mark thunderbird 2.0.0.23 and higher as safe

Approved by:    secteam (miwi)
Original commit
Thursday, 20 Aug 2009
19:37 wxs search for other commits by this committer
- Document pidgin, libpurple, and finch memory corruption.

PR:             ports/137997
Submitted by:   Armin Pirkovitsch <armin@frozen-zone.org>
Original commit
Monday, 17 Aug 2009
14:37 wxs search for other commits by this committer
- Document NUL byte problem in gnutls and gnutls-devel
- Document multiple vulnerabilities in older versions[1]

Note:  These have all been fixed with the exception of the NUL byte problem
in gnutls-devel.

PR:             [1]: ports/134785
Submitted by:   [1]: Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Reviewed by:    miwi
Original commit
13:26 mnag search for other commits by this committer
- memcached -- memcached stats maps Information Disclosure Weakness

PR:             134206
Submitted by:   Mark Foster <mark___foster.cc>
Original commit
Thursday, 13 Aug 2009
09:55 miwi search for other commits by this committer
- Update latest wordpress entry
   * add wordpress-mu which was also affected
- Mark latest fetchmail entry as safe
Original commit
Wednesday, 12 Aug 2009
14:57 skreuzer search for other commits by this committer
Document remote admin password reset vulnerability in wordpress <= 3.8.3

Reviewed by:    simon
Original commit
Tuesday, 11 Aug 2009
14:54 amdmi3 search for other commits by this committer
- Document fetchmail -- improper SSL certificate subject verification
Original commit
13:35 skreuzer search for other commits by this committer
Fix typo in affected version number for vid
739b94a4-838b-11de-938e-003048590f9e

Submitted by:   Roberto Nunnari <robi@nunnisoft.ch> (Private eMail)
Reviewed by:    simon
Original commit
Friday, 7 Aug 2009
21:24 skreuzer search for other commits by this committer
- Fix improper formatting reported by miwi

- Add additioinal reference url for vid 739b94a4-838b-11de-938e-003048590f9e
reported by miwi

Reviewed by:    miwi
Original commit
20:06 skreuzer search for other commits by this committer
Document com_mailto Timeout Issue in www/joomla15
Original commit
16:30 simon search for other commits by this committer
Cleanup whitespace and XML format using 'make tidy' and a bit manual
editing.
Original commit
13:18 simon search for other commits by this committer
Various affects fixes to the last 3 Mozilla/Firefox entries to make then
match correctly against package names.  In particular the port name
instead of package name was used in a couple of places.  For Seamonkey
and Thunderbird where no known fixes exist don't include a fixed
version.
Original commit
10:48 miwi search for other commits by this committer
- Update previous subversion entry,
  add missing p5-subversion and py-subversion
Original commit
09:31 miwi search for other commits by this committer
- Fix latest firefox entry.

Reported by:    b.f <bf1793@gmail.com>
Original commit
Thursday, 6 Aug 2009
21:41 simon search for other commits by this committer
Document subversion -- heap overflow vulnerability.
Original commit
Wednesday, 5 Aug 2009
23:23 simon search for other commits by this committer
Add a few CVE names to the 'squid -- several remote denial of service
vulnerabilities' entry.
Original commit
23:19 simon search for other commits by this committer
Document bugzilla -- product name information leak.
Original commit
Tuesday, 4 Aug 2009
23:15 miwi search for other commits by this committer
- Mark squid 3.1.0.12 as safe
Original commit
22:57 miwi search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
18:20 wxs search for other commits by this committer
- Add bind9-sdb-ldap and bind9-sdb-postgresql to recent BIND DoS.

Reviewed by:    miwi
Original commit
18:06 wxs search for other commits by this committer
- Document silc-client and silc-irssi-plugin format string vulnerability.

Reviewed by:    miwi
Original commit
Sunday, 2 Aug 2009
14:11 thierry search for other commits by this committer
Mark mail/squirrelmail-multilogin-plugin as FORBIDDEN and add the
corresponding entry in VuXML.

Security:       VuXML: 0d0237d0-7f68-11de-984d-0011098ad87f
Original commit
Saturday, 1 Aug 2009
14:25 wxs search for other commits by this committer
- White space fixes and correct the entry date in
  vid 83725c91-7c7e-11de-9672-00e0815b8da8
Original commit
14:17 wxs search for other commits by this committer
s/package/system/ for vid fbc8413f-2f7a-11de-9a3f-001b77d09812.

Reviewed by:    remko
Approved by:    secteam (remko)
Original commit
14:13 wxs search for other commits by this committer
- Document BIND DoS in base and ports.

Reviewed by:    remko
Approved by:    secteam (remko)
Original commit
Wednesday, 29 Jul 2009
16:17 miwi search for other commits by this committer
- Close tag
Original commit
16:00 miwi search for other commits by this committer
- Document Mono XML Signature HMAC Truncation Spoofing
Original commit
Monday, 27 Jul 2009
19:39 delphij search for other commits by this committer
Document squid remote denial of service vulnerabilities.

Submitted by:   Thomas-Martin Seck <tmseck@web.de>
PR:             ports/137184
Original commit
Wednesday, 22 Jul 2009
00:11 jpaetzel search for other commits by this committer
Fix security advsory with patches from Ubuntu project.
http://vuxml.FreeBSD.org/c444c8b7-7169-11de-9ab7-000c29a67389.html

PR:     ports/136891
Submitted by:   wxs@
Reviewed by:    simon@
Approved by:    itetcu@ (mentor)
Original commit
Friday, 17 Jul 2009
10:18 miwi search for other commits by this committer
- Fix a typo
Original commit
07:58 miwi search for other commits by this committer
- Document firefox35 -- corrupt JIT state after deep return from native function
Original commit
Wednesday, 15 Jul 2009
18:34 wxs search for other commits by this committer
- Document isc-dhcp*-client stack overflow.
Original commit
Tuesday, 14 Jul 2009
03:17 wxs search for other commits by this committer
- Tweak nagios version information a bit for the command injection
  vulnerability. Patches for net-mgmt/nagios and net-mgmt/nagios2 coming
  shortly.
Original commit
Monday, 13 Jul 2009
19:01 miwi search for other commits by this committer
- Document drupal -- multiple vulnerabilities

Submitted by:   Nick Hilliard (based on)
Original commit
Sunday, 12 Jul 2009
13:51 beat search for other commits by this committer
- Mark linux-firefox 3.0.11 and higher as safe

Approved by:    secteam (miwi)
Original commit
Friday, 3 Jul 2009
01:35 wxs search for other commits by this committer
- Document remote command execution in net-mgmt/nfsen

PR:             ports/136070
Submitted by:   Bjoern Engels <engels@openit.de>
Original commit
Thursday, 2 Jul 2009
20:38 wxs search for other commits by this committer
- Add syslog-ng package to the list of vulnerable versions for the chroot
  vulnerability.
Original commit
Wednesday, 1 Jul 2009
13:01 wxs search for other commits by this committer
- Add newly created CVE for nagios command injection vulnerability.
- Add the other two nagios packages to the list.
- Add modified entry accordingly.
Original commit
Tuesday, 30 Jun 2009
19:10 delphij search for other commits by this committer
Document phpMyAdmin XSS vulnerability
Original commit
14:13 wxs search for other commits by this committer
- Document nagios command injection vulnerability.
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48  »  [Last Page]