notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it is already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50  »  [Last Page]

Wednesday, 4 Mar 2009
15:30 roam search for other commits by this committer
Document the cURL redirection security bypass - CVE-2009-0037.
I'll update the ftp/curl port itself ASAP.

PR:             132299
Reported by:    Mark Foster <mark@foster.cc> (the PR),
                Daniel Bond <db@danielbond.org> (e-mail)
Original commit
Monday, 23 Feb 2009
20:48 marcus search for other commits by this committer
Bump the modified date for the previous Firefox change.

Requested by:   miwi
Original commit
20:41 marcus search for other commits by this committer
Correct the Firefox 2.0 version for the recent Firefox vulnerabilities.
Original commit
00:53 mnag search for other commits by this committer
- Add CVE entries for last lighttpd security issue.

Reported by:    Eygene Ryabinkin <rea-fbsd___codelabs.ru>
Original commit
Wednesday, 18 Feb 2009
18:06 glarkin search for other commits by this committer
- Update to 1.7.5
- Added UPDATING entry about incompatibility between 1.7.4 and 1.7.5
- Added vuln.xml entry for local file inclusion vulnerability in <1.7.5
- Added maintainer mode target in ZF Makefile to speed up fixups of
  pkg-plist output from genplist

Security:       cf495fd4-fdcd-11dd-9a86-0050568452ac
Security:       http://framework.zend.com/issues/browse/ZF-5748
Security:      
http://weierophinney.net/matthew/archives/206-Zend-Framework-1.7.5-Released-Important-Note-Regarding-Zend_View.html
Original commit
Tuesday, 17 Feb 2009
21:11 jadawin search for other commits by this committer
- Document dia -- remote command execution vulnerability

Reviewed by:    miwi
Original commit
Sunday, 15 Feb 2009
21:45 miwi search for other commits by this committer
- Document pycrypto -- ARC2 module buffer overflow

PR:             based on 131689
Submitted by:   Mark Foster <mark@foster.cc>
Original commit
18:23 marcus search for other commits by this committer
Update the latest firefox vulnerability ranges.
Original commit
13:29 kuriyama search for other commits by this committer
Minor whitespace nits.
Original commit
13:08 miwi search for other commits by this committer
- Update previous entry
   * remove duplicate bid entry
   * add more referens
   * fix whitespaces
Original commit
11:06 des search for other commits by this committer
Document Varnish 2.0 DoS.

PR:             ports/131690
Submitted by:   Mark Foster <mark@foster.cc>
Original commit
Friday, 13 Feb 2009
13:30 miwi search for other commits by this committer
- Document tor -- multiple vulnerabilites
Original commit
Wednesday, 11 Feb 2009
19:15 miwi search for other commits by this committer
- Fix portaudit conflict with www/firefox and www/firefox3
- Mark www/firefox and www/linux-firefox FORBIDDEN

Discussion by:  simon/stas
With hat:       secteam
Original commit
16:52 miwi search for other commits by this committer
- Fix latest firefox entry
Original commit
14:37 miwi search for other commits by this committer
- Document firefox -- multiple vulnerabilities
Original commit
14:15 glarkin search for other commits by this committer
- document codeigniter -- arbitrary script execution in the new
                          Form Validationclass
Original commit
13:36 jadawin search for other commits by this committer
- Document pyblosxom -- atom flavor multiple XML injection vulnerabilities

Reviewed by:    miwi
Original commit
10:15 miwi search for other commits by this committer
- Document typo3 -- cross-site scripting and information disclosure
Original commit
Tuesday, 10 Feb 2009
20:53 miwi search for other commits by this committer
- Update latest squid* entry
        Add CVE-2009-0478

Submitted by:   jadawin
Original commit
Monday, 9 Feb 2009
17:55 stas search for other commits by this committer
- Update ruby vuxml entries due to ruby19 version bump.
Original commit
15:31 miwi search for other commits by this committer
- Document amaya -- multiple buffer overflow vulnerabilities

PR:             based on 131508
Submitted by:   Mark Foster <mark@foster.cc>
Original commit
14:52 miwi search for other commits by this committer
- Document websvn -- multiple vulnerabilities

PR:             based on 130934
Submitted by:   Mark Foster <mark@foster.cc>
Original commit
14:20 miwi search for other commits by this committer
- Document phplist -- local file inclusion vulnerability

PR:             based on 130932
Original commit
14:04 miwi search for other commits by this committer
- Document squid -- remote denial of service vulnerability

PR:             based on 131431
Original commit
13:41 miwi search for other commits by this committer
- Fix topic s/typo/typo3
Original commit
13:30 miwi search for other commits by this committer
- Document typo3 -- Multiple Vulnerabilities
Original commit
Friday, 6 Feb 2009
19:59 miwi search for other commits by this committer
- Fix previous entry
Original commit
19:35 tmclaugh search for other commits by this committer
Security update for sudo to 1.6.9p20 for CVE 2009-0034

Changes:
- Only use the cached supplementory group vector when matching groups
  for the invoking user. (security)
- When setting the umask, use the union of the user's umask and the
  default value set in sudoers so that we never lower the user's umask
  when running a command.
- Sudo now operates in the C locale again when doing a match against
  sudoers.

PR:             131446
Submitted by:   Eygene Ryabinkin
Security:       vid:13d6d997-f455-11dd-8516-001b77d09812
Original commit
Wednesday, 4 Feb 2009
14:01 miwi search for other commits by this committer
- Fix a typo (s/drual/drupal)
Original commit
13:53 miwi search for other commits by this committer
- Cleanup
Original commit
13:47 miwi search for other commits by this committer
- Document drupal -- multible vulnerabilities
Original commit
06:47 ale search for other commits by this committer
Update php5-gd entry.
Original commit
Tuesday, 3 Feb 2009
21:42 miwi search for other commits by this committer
- Document perl -- Directory Permissions Race Condition

PR:             based on 129317
Original commit
Friday, 30 Jan 2009
09:55 miwi search for other commits by this committer
- Rework ganglia entry
  * Fix topic
  * Fix discovery and entry day
Original commit
09:13 miwi search for other commits by this committer
- Set modified for b9077cc4-6d04-4bcb-a37a-9ceaebfdcc9e entry
- more cleanup
Original commit
08:59 miwi search for other commits by this committer
- Document moinmoin -- multiple cross site scripting vulnerabilities
Original commit
08:51 miwi search for other commits by this committer
- Cleanup previous entry
        * remove whitespaces
        * sort bid/cvename/url
Original commit
03:56 brooks search for other commits by this committer
Upgrade Ganglia to 3.1.1 plus a fix for CVE-2009-0241.

PR:             ports/129822, ports/131067
Submitted by:   Mark Foster <mark at foster dot cc> (vuxml)
Security:       vid:b9077cc4-6d04-4bcb-a37a-9ceaebfdcc9e
Original commit
Thursday, 29 Jan 2009
22:49 miwi search for other commits by this committer
- Document Tor -- Unspecified Memory Corruption Vulnerability
Original commit
Wednesday, 28 Jan 2009
13:11 miwi search for other commits by this committer
- Cleanup
        * Fix whitespaces/ Tabs
        * Sort <bid>/<cvename>/<url>
Original commit
13:05 miwi search for other commits by this committer
- Rewording 2ffb1b0d-ecf5-11dd-abae-00219b0fc4d (glpi -- SQL Injection)
- Add more reference sites
Original commit
05:07 pgollucci search for other commits by this committer
Document glpi -- SQL Injection vulnerabilty

PR:             ports/131011
Submitted by:   Mathias Monnerville <mathias@monnerville.com>
Original commit
Sunday, 25 Jan 2009
00:56 tabthorpe search for other commits by this committer
- Document openfire -- multiple vulnerabilities

PR:             ports/130606
Submitted by:   Mark Foster <mark foster.cc>
Original commit
Saturday, 24 Jan 2009
02:31 delphij search for other commits by this committer
Update information about 9fff8dc8-7aa7-11da-bf72-00123f589060
and 651996e0-fe07-11d9-8329-000e0c2e438a, newer versions of
apache+ipv6 has the problems fixed.

Submitted by:   sumikawa
Original commit
Wednesday, 21 Jan 2009
19:44 wxs search for other commits by this committer
- Document two old ipsec-tools DoS

PR:             ports/129468
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
Tuesday, 20 Jan 2009
15:20 wxs search for other commits by this committer
- Document directory traversal bug in teamspeak server

PR:             ports/130608
Submitted by:   Mark Foster <mark@foster.cc>
Original commit
Monday, 19 Jan 2009
20:21 wxs search for other commits by this committer
- Document graphics/optipng buffer overflow

PR:             ports/129072
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
20:04 wxs search for other commits by this committer
- Document old gitweb privilege escalation vulnerability.

PR:             ports/130600
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
Friday, 16 Jan 2009
16:11 naddy search for other commits by this committer
Document vulnerability in older versions of GNU tar.

PR:             130602
Submitted by:   Mark Foster <mark@foster.cc>
Original commit
00:02 miwi search for other commits by this committer
- Mark net-mgmt/nagios2 as secure
Original commit
Thursday, 15 Jan 2009
23:00 miwi search for other commits by this committer
- Document mplayer -- vulnerability in STR files processor

PR:             based on 130573
Original commit
Tuesday, 13 Jan 2009
12:22 miwi search for other commits by this committer
- Cleanup previous entry
- Add more references
Original commit
03:30 wxs search for other commits by this committer
- Add missing blockquote and linewrap properly
Original commit
03:19 wxs search for other commits by this committer
- Document cgiwrap XSS vulnerability

PR:             ports/130277
Submitted by:   Eric W. Bates <ericx@vineyard.net>
Original commit
Monday, 12 Jan 2009
12:27 miwi search for other commits by this committer
- Document nagios -- web interface privilege escalation vulnerability
Original commit
Sunday, 11 Jan 2009
19:58 miwi search for other commits by this committer
- Document pdfjam -- insecure temporary files

PR:             based on 130028
Original commit
19:35 miwi search for other commits by this committer
- Document verlihub -- insecure temporary file usage and arbitrary command
execution
Original commit
18:16 miwi search for other commits by this committer
- Document mysql -- empty bit-string literal denial of service

PR:             based on 129978
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
15:38 miwi search for other commits by this committer
- Fix discovery date
Original commit
15:27 miwi search for other commits by this committer
- Document mysql multiple vulnerabilities:

        * mysql -- renaming of arbitrary tables by authenticated users
        * mysql -- remote Denial of Service via malformed password packet
        * mysql -- privilege escalation and overwrite of the system table
information

PR:             based on 130025
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
14:49 miwi search for other commits by this committer
- Document imap-uw -- imap c-client buffer overflow

PR:             130013
Submitted by:   Mark Foster <mark@foster.cc>
Approved by:    maintainer timeout
Original commit
14:32 miwi search for other commits by this committer
- Fix a small typo
Original commit
14:29 miwi search for other commits by this committer
- Document imap-uw -- local buffer overflow vulnerabilities

PR:             128923
Submitted by:   Mark Foster <mark@foster.cc>
Approved by:    maintainer timeout
Original commit
13:15 miwi search for other commits by this committer
- Document libcdaudio -- remote buffer overflow and code execution
Original commit
Tuesday, 6 Jan 2009
04:31 tabthorpe search for other commits by this committer
- Mark xterm 238 safe
Original commit
Monday, 5 Jan 2009
10:09 remko search for other commits by this committer
Import latest FreeBSD-SA's so that we are up to date again.
Original commit
09:40 stas search for other commits by this committer
- Document xterm vulnerability.
Original commit
09:06 stas search for other commits by this committer
- Document PHP gd library vulnerability.
Original commit
Sunday, 4 Jan 2009
09:13 miwi search for other commits by this committer
- Update awstats entry (also affect www/awstats-devel)
Original commit
08:01 chinsan search for other commits by this committer
- Fix the affected version of awstats
Original commit
06:21 chinsan search for other commits by this committer
- Document awstats -- multiple XSS vulnerabilities

PR:             ports/129957
Submitted by:   Eygene Ryabinkin <rea-fbsd _at\ codelabs.ru>
Approved by:    Alex Samorukov (maintainer)
Security:       http://secunia.com/advisories/31519
Original commit
Saturday, 3 Jan 2009
12:35 miwi search for other commits by this committer
- Cleanup (fix whitespaces, typos)
Original commit
12:06 chinsan search for other commits by this committer
- Completely fix CVE-2005-0448

PR:             ports/129301
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
Friday, 2 Jan 2009
09:56 erwin search for other commits by this committer
Bump copyright year.
Original commit
04:44 tabthorpe search for other commits by this committer
- Document vim -- multiple vulnerabilities in the netrw module

PR:             ports/129137
Submitted by:   Eygene Ryabinkin <rea-fbsd codelabs.ru>
Original commit
Wednesday, 31 Dec 2008
21:23 mezz search for other commits by this committer
Add vinagre -- format string vulnerability entry.

PR:             ports/129959
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
Tuesday, 30 Dec 2008
19:16 glarkin search for other commits by this committer
Document twiki - multiple vulnerabilities
Original commit
17:09 ale search for other commits by this committer
Add entry for roundcube.

Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
11:12 miwi search for other commits by this committer
- Document mysql -- MyISAM table privileges security bypass vulnerability for
symlinked paths
Original commit
09:29 miwi search for other commits by this committer
- Document mplayer -- twinvq processing buffer overflow vulnerability

Reported by:    Thomas Zander <riggs@rrr.de> (mplayer maintainer)
Original commit
Friday, 26 Dec 2008
09:22 jadawin search for other commits by this committer
- ampache -- insecure temporary file usage
Original commit
Thursday, 25 Dec 2008
16:41 miwi search for other commits by this committer
- Small cleanup for the last cups-base entry
  * CVE-2008-5184 was fixed in 1.3.8.
  * CVE-2008-1722 does not related to anything in this entry;
  * PNG buffer overflow is really CVE-2008-5286.

Reported by:    Eygene Ryabinkin <rea-fbsd@codelabs.ru>
No Cookies for: miwi
Original commit
Friday, 19 Dec 2008
21:07 miwi search for other commits by this committer
- Document opera -- multiple vulnerabilities
Original commit
21:00 miwi search for other commits by this committer
- Document mediawiki -- multiple vulnerabilities
Original commit
20:36 miwi search for other commits by this committer
- Fix make validate
Original commit
20:29 miwi search for other commits by this committer
- document drupal -- Multiple vulnerabilities
Original commit
20:01 miwi search for other commits by this committer
- Document mozilla -- multiple vulnerabilities
Original commit
Thursday, 11 Dec 2008
19:39 miwi search for other commits by this committer
- Fix a small typo
Original commit
19:37 miwi search for other commits by this committer
- Document phpmyadmin -- cross-site request forgery vulnerability
Original commit
Monday, 8 Dec 2008
14:15 tabthorpe search for other commits by this committer
- Document php5 -- potential magic_quotes_gpc vulnerability

Reviewed by:    miwi
Original commit
Sunday, 7 Dec 2008
19:13 miwi search for other commits by this committer
- Fix a typo

Reported by:    Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
18:11 miwi search for other commits by this committer
- Document wireshark --  SMTP Processing Denial of Service Vulnerability
Original commit
12:13 miwi search for other commits by this committer
- Document php -- multiple vulnerabilities
Original commit
11:41 miwi search for other commits by this committer
- Document mgetty+sendfax -- symlink attack via insecure temporary files

PR:             based on 129471
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
11:32 miwi search for other commits by this committer
- Document dovecot-managesieve -- Script Name Directory Traversal Vulnerability

PR:             based on 129303
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit
11:20 miwi search for other commits by this committer
Document habari -- Cross-Site Scripting Vulnerability

PR:             129475
Submitted by:   Ayumi M <ayu@dahlia.commun.jp>
Original commit
09:09 miwi search for other commits by this committer
- Add 32545 to the latest vlc entry.
Original commit
Saturday, 6 Dec 2008
23:47 miwi search for other commits by this committer
- Document vlc -- arbitrary code execution in the RealMedia processor
Original commit
23:18 miwi search for other commits by this committer
- S/secunia/Secunia
Original commit
22:00 miwi search for other commits by this committer
- Document mantis - PHP Code Execution Vulnerability

PR:             based on 129438
Submitted by:   Eygene Ryabinkin <rea-fbsd@codelabs.ru>
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50  »  [Last Page]