notbug ipv6 ready As an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photos
All times are UTC
Ukraine
The recently imposed "must be logged in" restriction is a response to increased bot traffic on the site. This affects search, commits, and vuxml pages.
Search engines are not blocked. Try using "site:www.freshports.org" and your search terms.
non port: security/vuxml/vuln.xml

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53  »  [Last Page]

Wednesday, 5 Mar 2008
07:13 rafan search for other commits by this committer
- Entry for ghostscrip-gpl 8.61

Reviewed by:    ports-security@ (simon, remko)
Original commit
01:01 tabthorpe search for other commits by this committer
- Document phpmyadmin -- SQL injection vulnerability

Reviewed by:    simon
Original commit
Saturday, 1 Mar 2008
04:08 tabthorpe search for other commits by this committer
- Document pcre -- buffer overflow vulnerability

PR:             ports/121224
Submitted by:   Nick Barkas <snb threerings.net>
Original commit
Thursday, 28 Feb 2008
01:41 tabthorpe search for other commits by this committer
- Document libxine -- buffer overflow vulnerability

Reviewed by:    miwi
Original commit
Wednesday, 27 Feb 2008
09:33 miwi search for other commits by this committer
- Mark mail/up-imapproxy as safe

Submitted by:   Abdullah Ibn Hamad Al-Marri <wearabnet@yahoo.ca>
Original commit
Tuesday, 26 Feb 2008
12:43 tabthorpe search for other commits by this committer
- Document coppermine -- multiple vulnerabilities.

Reviewed by:    miwi
Original commit
12:34 miwi search for other commits by this committer
- Fix previous commit (use now <bid>)
Original commit
Monday, 25 Feb 2008
18:38 tabthorpe search for other commits by this committer
- Document moinmoin -- multiple vulnerabilities.

Reviewed by:    remko
Original commit
Friday, 22 Feb 2008
00:56 simon search for other commits by this committer
Document opera -- multiple vulnerabilities.
Original commit
00:43 simon search for other commits by this committer
Document mozilla -- multiple vulnerabilities.
Original commit
00:26 delphij search for other commits by this committer
Document openldap modrdn DoS vulnerability
Original commit
Friday, 15 Feb 2008
10:23 remko search for other commits by this committer
Document clamav -- ClamAV libclamav PE File Integer Overflow Vulnerability

Submitted by:   "Eygene Ryabinkin" <rea-fbsd at codelabs dot ru>
Original commit
Wednesday, 13 Feb 2008
17:20 miwi search for other commits by this committer
- Fix previous commit

Discussed with: remko
Original commit
16:37 remko search for other commits by this committer
Bump modification date for latest change.
Original commit
15:32 oliver search for other commits by this committer
xfce4-panel, libxfce4gui - mark the security problem which existed in 4.4.1 "<
4.4.2"

Noted by:       Carl Johan Gustavsson <carl.gustavsson@bahnhofbredband.se>
Original commit
Tuesday, 12 Feb 2008
22:14 miwi search for other commits by this committer
- mark claws-mail as safe
Original commit
13:30 sem search for other commits by this committer
- Document a cacti vulnerability
Original commit
08:48 brix search for other commits by this committer
Add entry for www/ikiwiki.

Approved by:    erwin (mentor)
Original commit
Saturday, 9 Feb 2008
18:47 tabthorpe search for other commits by this committer
- Fix grammar for www/zenphoto description
Original commit
14:39 tabthorpe search for other commits by this committer
- Document www/zenphoto

Reviewed by:    remko
Original commit
11:16 miwi search for other commits by this committer
- Fix a typo

Submitted by:   antoine@
Original commit
Monday, 4 Feb 2008
07:58 miwi search for other commits by this committer
- Document jetty -- multiple vulnerability

PR:             120171
Submitted by:   Nick Barkas <snb@threerings.net>
Original commit
Thursday, 31 Jan 2008
14:47 miwi search for other commits by this committer
- Bump modified from previous commit
Original commit
04:06 linimon search for other commits by this committer
Fix name of irc/dircproxy package.

Hat:            portmgr
Original commit
Tuesday, 29 Jan 2008
15:14 nobutaka search for other commits by this committer
Document libxine -- buffer overflow vulnerability.
Original commit
Wednesday, 23 Jan 2008
12:11 flz search for other commits by this committer
Document xorg -- multiple vulnerabilities.

Reviewed by:    miwi
Original commit
Tuesday, 22 Jan 2008
22:18 miwi search for other commits by this committer
- Fix discovery line from the previous commit :(
Original commit
22:01 miwi search for other commits by this committer
- Document xfce -- multiple vulnerabilities
Original commit
21:38 miwi search for other commits by this committer
- Document claws-mail -- insecure temporary file creation
Original commit
Sunday, 20 Jan 2008
10:04 miwi search for other commits by this committer
- Add modified date for previous commit
Original commit
02:28 lwhsu search for other commits by this committer
- Fix freeradius-devel entry, narrow down range to prevent affect later versions

PR:             ports/119582
Submitted by:   David Wood <david AT wood2.org.uk>
Reviewed by:    pav
Original commit
01:35 miwi search for other commits by this committer
- Fix previous commit (whitespaces, sorting)
Original commit
01:21 beech search for other commits by this committer
- Add entry for ircservices

PR:             ports/119769
Approved by:    linimon (mentor)
Original commit
Saturday, 19 Jan 2008
18:03 nobutaka search for other commits by this committer
Document libxine -- buffer overflow vulnerability.
Original commit
09:50 skv search for other commits by this committer
Update the "firebird" entry to properly match corrected versions.
Original commit
Tuesday, 15 Jan 2008
22:43 miwi search for other commits by this committer
- Fix <name> sections from both previous committs
Original commit
20:15 miwi search for other commits by this committer
- Fix previous commit
  - Mark geeklog as safe
  - add cve

Reviewed by:    remko
Original commit
18:52 tabthorpe search for other commits by this committer
- Document XSS vulnerability in geeklog 1.4.0

Reviewed by:    remko
Original commit
Monday, 14 Jan 2008
15:56 stas search for other commits by this committer
- This vulnerability exists in PHP versions prior to 4.4.8, not
  after. Fix the entry.

Reported by:    Vadim Goncharov <vadimnuclight@tpu.ru>
Original commit
Saturday, 12 Jan 2008
15:53 simon search for other commits by this committer
Document multiple drupal issues.

Submitted by:   Nick Hilliard <nick@foobar.org>
Original commit
Thursday, 10 Jan 2008
19:38 miwi search for other commits by this committer
- Document maradns -- CNAME record resource rotation denial of service

PR:             ports/119471 (based on)
Submitted by:   Mark D. Foster <mark@foster.cc>
Reviewed by:    simon
Original commit
Monday, 7 Jan 2008
22:48 miwi search for other commits by this committer
- Mark security/lsh as safe
Original commit
Friday, 4 Jan 2008
18:52 delphij search for other commits by this committer
Update php multiple vulnerability entry: revalent bugs were fixed in PHP 4.4.8.
Original commit
18:48 mnag search for other commits by this committer
- Fix linux-realplayer new version
Original commit
18:45 mnag search for other commits by this committer
- Fix range for linux-flahsplugin
Original commit
18:07 mnag search for other commits by this committer
- linux-realplayer -- multiple vulnerabilities
Original commit
Thursday, 3 Jan 2008
13:13 mnag search for other commits by this committer
- linux-flashplugin -- multiple vulnerabilities
Original commit
Monday, 31 Dec 2007
11:59 miwi search for other commits by this committer
- Fix the last tcl/tk entry for portaudit.

Submitted by:   mm@
Reviewed by:    simon
Original commit
Sunday, 30 Dec 2007
09:35 delphij search for other commits by this committer
Document dovecot specific LDAP + auth cache configuration may mix up user logins
vulnerability
Original commit
Saturday, 29 Dec 2007
20:28 simon search for other commits by this committer
Add more references to latest opera entry.
Original commit
19:49 simon search for other commits by this committer
Make "gallery2 -- multiple vulnerabilities" follow the normal format for
VuXML entries.
Original commit
Tuesday, 25 Dec 2007
08:14 beech search for other commits by this committer
- Document gallery2 -- multiple vulnerabilities

Submitted by:   Alex Varju <freebsd-ports@varju.ca> (maintainer)
Approved by:    linimon (mentor)
Original commit
Saturday, 22 Dec 2007
14:26 simon search for other commits by this committer
Update list if CVE names for latest wireshark entry.
Original commit
Friday, 21 Dec 2007
21:43 miwi search for other commits by this committer
- Document e2fsprogs -- heap buffer overflow

PR:             118848 (based on)
Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Reviewed by:    remko
Original commit
Wednesday, 19 Dec 2007
23:03 simon search for other commits by this committer
Document wireshark -- multiple vulnerabilities.
Original commit
21:06 simon search for other commits by this committer
Document opera -- multiple vulnerabilities.
Original commit
20:52 simon search for other commits by this committer
Document peercast -- buffer overflow vulnerability.
Original commit
Tuesday, 18 Dec 2007
13:06 simon search for other commits by this committer
Unbreak vuln.xml: & -> &amp;

Pointy hat to:  brooks
Original commit
Monday, 17 Dec 2007
22:24 brooks search for other commits by this committer
Upgrade to Ganglia 3.0.6.

Release 3.0.5 contained minor bug fixes.  3.0.6 corrects XSS
vulnerabilities in the webfrontend.

Security:        vid:fee7e059-acec-11dc-807f-001b246e4fdf
Original commit
Friday, 14 Dec 2007
19:55 remko search for other commits by this committer
Sort references section for last commit.
Original commit
00:17 sat search for other commits by this committer
- Mark latest linux-firefox/seamonkey-devel snapshots as safe
- Add (linux-)flock and linux-*-devel to latest firefox advisory
- Note that the tradition of covering more gecko ports with
  firefox-related advisories should probably be kept up
Original commit
Thursday, 13 Dec 2007
00:36 nox search for other commits by this committer
Document qemu -- Translation Block Local Denial of Service Vulnerability
Original commit
Wednesday, 12 Dec 2007
15:48 remko search for other commits by this committer
Document drupal -- SQL injection vulnerability

Submitted by:   Nick Hilliard <nick at netability dot ie>
Original commit
15:29 remko search for other commits by this committer
Document samba -- buffer overflow vulnerability.
Original commit
15:11 remko search for other commits by this committer
Remove redundant "A" in the latest entry
Original commit
08:32 miwi search for other commits by this committer
- Fix previous commit
   - Sorting
   - more referencs
Original commit
08:11 beech search for other commits by this committer
- Missed a section - smbftpd

Pointyhat to: Self
Original commit
07:55 beech search for other commits by this committer
- Document smbftpd - format string vulnerability.

Requested by:   linimon
Approved by:    linimon (mentor)
Original commit
Monday, 10 Dec 2007
07:00 remko search for other commits by this committer
Document jetty - multiple vulnerabilities

PR:             ports/118524
Submitted by:   Nick Barkas <snb at threerings dot net>
                with minor modifications by me
Approved by:    portmgr (secteam blanket)
Original commit
Sunday, 9 Dec 2007
15:47 nork search for other commits by this committer
Update to 2007.12.07 with fix security issue.

Security:       VuXML ID: 821afaa2-9e9a-11dc-a7e3-0016360406fa
                CVE-2007-6036
                http://aluigi.altervista.org/adv/live555x-adv.txt
Approved by:    portmgr (erwin)
Original commit
Saturday, 8 Dec 2007
23:26 remko search for other commits by this committer
Document liveMedia -- DoS vulnerability

Submitted by:   Rafae«l Careé <funm at videolan dot org>
                with modifications by me
Approved by:    portmgr (secteam blanket)
Original commit
Friday, 7 Dec 2007
10:25 delphij search for other commits by this committer
Update to reflect the squid issue has been assigned
CVE-2007-6239.

Approved by:    portmgr (ports-security blanket)
Original commit
Wednesday, 5 Dec 2007
07:49 miwi search for other commits by this committer
- Update gnu-finger entry
        * Fix cvename handling

Approved by:    portmgr (ports-security blanket)
Original commit
07:27 linimon search for other commits by this committer
http://nvd.nist.gov/nvd.cfm?cvename=CVE-1999-1165: gnu-finger is old,
creaky, and not for use in production environments.

Submitted by:   tabthorpe
Approved by:    portmgr (self)
Original commit
00:28 delphij search for other commits by this committer
Update to reflect an updated www/squid30 version which is no
longer vulnerable.

Approved by:    portmgr (ports-security blanket)
Original commit
Tuesday, 4 Dec 2007
19:49 delphij search for other commits by this committer
Update to reflect an updated www/squid version which is no
longer vulnerable.

Approved by:    portmgr (ports-security blanket)
Original commit
19:20 delphij search for other commits by this committer
Document squid denial of service vulnerability.  This can be
triggered from trusted squid client only.

Approved by:    portmgr (ports-security blanket)
Original commit
Sunday, 2 Dec 2007
00:15 delphij search for other commits by this committer
Remove the rsync entry for now.  Better way of handling
this is still under discussion, as the vendor patch does
not automatically resolve problem for customized
configuration that have chroot = no.

Requested by:   pav
Approved by:    portmgr (ports-security blanket)
Original commit
Saturday, 1 Dec 2007
20:23 delphij search for other commits by this committer
Document rsync security bypass vulnerability.

Approved by:    portmgr (ports-security blanket)
Original commit
14:25 simon search for other commits by this committer
Make the rubygem-rails -- JSON XSS vulnerability entry valid UTF-8 (at
least the special chars doesn't look like UTF-8 as per emacs or
freshports).

Reported by:    freshports via dvl
Approved by:    portmgr (secteam blanket)
Original commit
Wednesday, 28 Nov 2007
00:26 delphij search for other commits by this committer
Also cover rubygem-activesupport which is part of rails and is
affected by CVE-2007-3227 as well.

Approved by:    portmgr (ports-security blanket)
Original commit
00:19 delphij search for other commits by this committer
Document recent Ruby On Rails vulnerabilities.

Approved by:    portmgr (ports-security blanket)
Original commit
Tuesday, 27 Nov 2007
21:57 brix search for other commits by this committer
Document ikiwiki improper symlink verification vulnerability.

Reviewed by:    remko
Approved by:    portmgr (erwin), erwin (mentor)
Original commit
21:35 delphij search for other commits by this committer
Document firefox multiple unspecified memory corruption vulnerabilities.

Approved by:    portmgr (ports-security blanket)
Original commit
Wednesday, 21 Nov 2007
18:58 miwi search for other commits by this committer
- Document phpmyadmin -- Cross Site Scripting

Reviewed by:    remko
Approved by:    portmgr (ports-security blanket
Original commit
09:02 miwi search for other commits by this committer
- Update last Samba entry,
        * Add reference to the samba advisories
        * Fix the PORTVERSION/PORTEPOCH

Reviewed by:    simon
Approved by:    portmgr (ports-security blanket)
Original commit
07:40 miwi search for other commits by this committer
 Document samba - multiple vulnerabilities

Reviewed by:    remko
Approved by:    portmgr (ports-security blanket)
Original commit
Sunday, 18 Nov 2007
00:47 delphij search for other commits by this committer
postnuke 0.763 is not vulnerable to 35f2679f-52d7-11db-8f1a-000a48049292
so mark it as not vulnerable.

Approved by:    portmgr (ports-security blanket)
Original commit
Saturday, 17 Nov 2007
07:07 delphij search for other commits by this committer
Improve JDK version coverage.  We should consider PORTEPOCH'ed version
separately, so restruct the range.

Approved by:    portmgr (ports-security blanket)
Original commit
Friday, 16 Nov 2007
19:53 delphij search for other commits by this committer
Document PHP multiple vulnerabilities that are fixed by php 5.2.5.

Approved by:    portmgr (ports-security blanket)
Original commit
08:05 miwi search for other commits by this committer
- Fix c93e4d41-75c5-11dc-b903-0016179b2dd5 entry

Submitted by:   glewis
Reviewed by:    remko
Approved by:    portmgr (ports-security blanket)
Original commit
Wednesday, 14 Nov 2007
22:19 erwin search for other commits by this committer
print/cups-base is vulnerable for all previous versions to
1.3.3_2, not all coming ones.

Submitted by:   Andrew Daugherity <ADaugherity@vprmail.tamu.edu>
Approved by:    portmgr (self)
Original commit
14:23 remko search for other commits by this committer
Document mt-daapd -- denial of service vulnerability, also
correct the previous entry style wise.

Submitted by:   Mark D. Foster <mark at foster dot cc> with minor
                modifications by me.

Approved by:    portmgr (secteam blanket)
Original commit
09:23 miwi search for other commits by this committer
- Update xpdf -- multiple remote Stream.CC vulnerabilities
         * Mark cups-base as safe

Approved by:    portmgr (ports-security blanket)
Original commit
05:45 kuriyama search for other commits by this committer
o Add a patch for CVE-2007-5846, and add an entry for vuxml.

Approved by:  portmgr (marcus)
Original commit
Tuesday, 13 Nov 2007
15:41 miwi search for other commits by this committer
- Document flac -- media file processing integer overflow vulnerabilities

Reviewed by:    simon
Approved by:    portsmgr (ports-security blanket)
Thanks to:      naddy
Original commit
06:46 simon search for other commits by this committer
Unbreak file by closing </li> tag.

Approved by:    portmgr (secteam blanket)
Original commit
01:14 delphij search for other commits by this committer
Document xpdf arbitrary code execution vulnerability, as documented in
CVE-2007-4352, CVE-2007-5392, CVE-2007-5393.

Approved by:    portmgr (ports-security blanket)
Original commit
Monday, 12 Nov 2007
19:46 delphij search for other commits by this committer
dinoex@ has choosen to apply a vendor patch that has resolved CVE-2007-4351
instead of upgrading to 1.3.4.  Mark this updated version as not vulnerable.

Approved by:    portmgr (ports-security blanket)
Original commit
00:39 delphij search for other commits by this committer
Document plone arbitrary code execution vulnerability.

Approved by:    portmgr (ports-security blanket)
Original commit

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53  »  [Last Page]