notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Remember
I remember
I started running short on disk space for the non-production FreshPorts hosts. This time, I have decided to ask for donations. See my recent blog post which points to my Patreon account.
non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55  »  [Last Page]

Tuesday, 24 Jul 2007
13:54 delphij search for other commits by this committer
Document multiple vulnerabilities found in www/tomcat41
Original commit
08:00 delphij search for other commits by this committer
Document dokuwiki spellchecker XSS vulnerabilities
Original commit
Saturday, 21 Jul 2007
15:09 simon search for other commits by this committer
Fix last commit: the name tag was empty.

Reported by:    FreshPorts via Dan Langille
Pointyhat to:   delphij
Original commit
14:10 delphij search for other commits by this committer
Document lighttpd multiple vulnerabilities
Original commit
Thursday, 19 Jul 2007
22:27 simon search for other commits by this committer
Add another reference to mozilla -- multiple vulnerabilities.
Original commit
21:47 simon search for other commits by this committer
- Document opera -- multiple vulnerabilities.
- Correct and sort a few links in the latest mozilla entry.
Original commit
21:23 simon search for other commits by this committer
Document mozilla -- multiple vulnerabilities.
Original commit
Wednesday, 18 Jul 2007
06:43 delphij search for other commits by this committer
Document linuxflashplugin critical vulnerabilities.

Reported by:    jamie at bishopston net
Original commit
Monday, 9 Jul 2007
14:03 miwi search for other commits by this committer
- Fix the versions number of typespeed from 4.1.0 to 0.4.1

PR:             114441
Submitted by:   Tor Halvard Furulund <squat@squat.no>
Original commit
Saturday, 7 Jul 2007
08:27 sat search for other commits by this committer
- Fix the latest wireshark entries by correcting a typo and adding
  more package names
Original commit
Friday, 6 Jul 2007
10:34 miwi search for other commits by this committer
- Document wireshark - Multiple problems

Reviewed by:    simon@
Original commit
Tuesday, 3 Jul 2007
19:50 gabor search for other commits by this committer
- Document typespeed arbitrary code execution

Reviewed by:    remko
Original commit
Friday, 29 Jun 2007
22:18 miwi search for other commits by this committer
- Fix a typo vcl -> vlc

Noticed by:     lx@
Original commit
09:42 miwi search for other commits by this committer
- Document vlc - format string vulnerability and integer overflow
Original commit
09:24 miwi search for other commits by this committer
- Document flac123 - stack overflow in comment parsing

Reviewed by:    simon@
Original commit
06:06 remko search for other commits by this committer
Document gd -- multiple vulnerabilities

PR:             ports/114115
Submitted by:   Nick Barkas <snb at threerings dot net> (minor modifications by
me).
Original commit
Thursday, 28 Jun 2007
07:38 delphij search for other commits by this committer
Document that CVE-2007-3257 was fixed with evolution-data-server
1.10.2_1.
Original commit
Wednesday, 27 Jun 2007
20:52 sat search for other commits by this committer
- Fix modified date in mod_perl entry
Original commit
20:44 erwin search for other commits by this committer
Mark www/mod_perl2 fixed in version 2.0.3_2,3
Original commit
Monday, 25 Jun 2007
10:57 delphij search for other commits by this committer
Document evolution-data-server remote arbitrary code execution
vulnerability.

Fix at: Evolution SVN changeset 7817 (#447414)
Original commit
Sunday, 24 Jun 2007
11:34 erwin search for other commits by this committer
The XMLRPC SQL Injection issue with wordpress was addressed in the
latest release.
Original commit
Thursday, 21 Jun 2007
17:28 gabor search for other commits by this committer
Document xpcd buffer overflow vulnerability.

Revieved by:    remko
Original commit
Tuesday, 19 Jun 2007
19:47 remko search for other commits by this committer
Document clamav -- multiple vulnerabilities.
Original commit
Monday, 18 Jun 2007
07:56 delphij search for other commits by this committer
Document SpamAssassin vulnerability CVE-2007-2873, a local
DoS issue.
Original commit
Tuesday, 12 Jun 2007
18:27 miwi search for other commits by this committer
- Document cups -- Incomplete SSL Negotiation Denial of Service.

Reviewed by:    simon@
Original commit
Saturday, 9 Jun 2007
19:47 miwi search for other commits by this committer
- Fix other duplicate entry.

Reviewed by:    simon
Original commit
17:46 miwi search for other commits by this committer
- Document c-ares -- DNS Cache Poisoning Vulnerability

Reviewed by:    simon@
Original commit
17:44 miwi search for other commits by this committer
- Fix duplicate entry de-wordpress -> zh-wordpress.
Original commit
16:13 gabor search for other commits by this committer
Add zh-wordpress as affected by the last two wordpress entries.
Original commit
15:07 gabor search for other commits by this committer
wordpress -- XMLRPC SQL Injection
wordpress -- unmoderated comments disclosure

Reviewed by:    simon
Original commit
14:07 miwi search for other commits by this committer
- Document webmin -- cross site scripting

Reviewed by:    simon@
Original commit
Thursday, 7 Jun 2007
18:34 simon search for other commits by this committer
- The fixed mplayer version number is 0.99.10_10, mark it as such. [1]
- Add older mplayer package names.
- Break long lines.

Noticed by:     Henrik Brix Andersen <henrik@brixandersen.dk>
Original commit
08:44 miwi search for other commits by this committer
- Fix mplayer portversion.
Original commit
08:42 miwi search for other commits by this committer
- Document mplayer -- cddb stack overflow.

Reviewed by:    simon@
Original commit
Wednesday, 6 Jun 2007
09:29 gabor search for other commits by this committer
- Note that plone is also affected by 34414a1e-e377-11db-b8ab-000c76189c4c
  prior to version 2.5.3

Reviewed by:    simon
Original commit
Tuesday, 5 Jun 2007
16:17 gabor search for other commits by this committer
- gzip 1.3.12 has been patched and is not affected by
  11a84092-8f9f-11db-ab33-000e0c2e438a any more

Reviewed by:    simon
Original commit
09:38 erwin search for other commits by this committer
Document an information disclosure vulnerability in mod_jk < 1.2.23.

Reviewed by:    simon
Original commit
Monday, 4 Jun 2007
20:56 erwin search for other commits by this committer
Add an entry for an email header injection vulnerability in
www/typo3 from February.

Reviewed by:    remko
Persuaded by:   cperciva and simon by setting up the
                ports-security team
Original commit
12:42 miwi search for other commits by this committer
- Document phppgadmin - Cross Site Scripting Vulnerability.

Reviewed by:    mnag@
Reported by:    dinoex@
Original commit
Friday, 1 Jun 2007
19:36 trasz search for other commits by this committer
- Add entry for findutils -- GNU locate heap buffer overrun.

Revieved by:    simon (secteam)
Approved by:    miwi (mentor)
Original commit
Thursday, 31 May 2007
08:05 delphij search for other commits by this committer
Mark file < 4.21 as vulnerable to the heap overflow.
Original commit
Friday, 25 May 2007
00:37 marcus search for other commits by this committer
Add an entry for the recent Freetype heap overflow vulnerability.

Submitted by:   Nick Barkas <snb@threerings.net>
Original commit
Wednesday, 23 May 2007
16:29 remko search for other commits by this committer
Document FreeBSD-SA-07:04.file (heap overflow in file(1))

Approved by:    portmgr (secteam implicit)
Original commit
Monday, 21 May 2007
20:08 miwi search for other commits by this committer
- Document squirrelmail -- Cross site scripting in HTML filter

Approved by:    portmgr (marcus)
Original commit
Wednesday, 16 May 2007
21:10 simon search for other commits by this committer
Document png -- DoS crash vulnerability.
Original commit
20:22 simon search for other commits by this committer
Document samba -- multiple vulnerabilities.

Brought to you from Heathrow Airport and BSDCan 2007 Devsummit.
Original commit
Thursday, 10 May 2007
17:31 simon search for other commits by this committer
Update PHP entry to include the vulnerable version so the entry is
correct for when PHP is updated in ports (yes it's being worked on),
or for people who upgrade "manually".

With hat:       secteam
Requested by:   several
Original commit
Monday, 7 May 2007
09:12 remko search for other commits by this committer
Document a lot of PHP vulnerabilities, mark all php4 and php5 (+cli,cgi)
ports as vulnerable till the ports had been upgraded.
Original commit
08:49 remko search for other commits by this committer
Bump modification date for the latest mod_perl entry, this was forgotten
by erwin, but there were "massive" changes that warrant a date bump.
Original commit
Wednesday, 2 May 2007
16:56 remko search for other commits by this committer
Standarize the latest entry (qemu) a bit more and add a forgotten 'a'
in the p5-Imager text.
Original commit
Tuesday, 1 May 2007
22:49 nox search for other commits by this committer
Document multiple qemu vulnerabilities

Obtained from:  debian-security-announce@lists.debian.org mailing list
Security:       multiple qemu vulnerabilities
Original commit
Monday, 30 Apr 2007
17:51 lbr search for other commits by this committer
Update to 0.57 - fixes possible overflow vulnerability regarding malformed
BMPs, see vuln.xml for details.

Security:       VuXML ID: 632c98be-aad2-4af2-849f-41a6862afd6a
Original commit
Saturday, 28 Apr 2007
18:34 remko search for other commits by this committer
Document FreeBSD -- IPv6 Routing Header 0 is dangerous
Original commit
Wednesday, 25 Apr 2007
19:05 erwin search for other commits by this committer
Rework the mod_perl entry to note that Mandriva originally released
an advisory.  Also add mod_perl2 to the vulnerable versions.
Original commit
17:11 erwin search for other commits by this committer
Minor wordsmithing in the last mod_perl entry.

Submitted by:   simon
Original commit
17:04 erwin search for other commits by this committer
Add entry for mod_perl -- remote DOS in PATH_INFO parsing

PR:             111844
Submitted by:   "Philip M. Gollucci" <pgollucci@p6m7g8.com>
Original commit
Monday, 23 Apr 2007
14:12 tobez search for other commits by this committer
p5-Crypt-OpenPGP 1.03_1 should not be vulnerable to CVE-2005-0366.
Original commit
Thursday, 19 Apr 2007
11:55 sat search for other commits by this committer
- Mark latest firefox and seamonkey snapshots as safe
Original commit
10:37 miwi search for other commits by this committer
- Add entry for claws-mail - APOP vulnerability
Original commit
Saturday, 14 Apr 2007
15:11 mnag search for other commits by this committer
lighttpd -- DOS when access files with mtime 0
lighttpd -- Remote DOS in CRLF parsing
Original commit
Friday, 13 Apr 2007
15:46 stas search for other commits by this committer
- Add freeradius-mysql to the list of affected packages of the recent
  freeradius entry.

Submitted by:   David Wood <david@wood2.org.uk>
Original commit
11:50 flz search for other commits by this committer
Mark Google Earth >= 4.0.2414 as safe.
Original commit
08:19 stas search for other commits by this committer
- Document recent remote dos vulnerability in freeradius.
Original commit
Tuesday, 10 Apr 2007
21:10 simon search for other commits by this committer
Add an extra reference to the old "gnupg -- OpenPGP symmetric
encryption vulnerability" entry which explains the problem in a more
easy to read way.

Submitted by:   tobez (sort of)
Original commit
Monday, 9 Apr 2007
20:05 barner search for other commits by this committer
Document fetchmail's "insecure APOP authentication" issue (fixed in 6.3.8).
Original commit
Sunday, 8 Apr 2007
19:58 remko search for other commits by this committer
Stylify the latest zope entry:

o Use consistent title description
o Use tabs when 8 spaces are hit
o Sort the references list (the alphabet goes from a to z)
o Bump modification date (note: please check the entry date
  so that it matches the correct data of insertion).

Also stylify the latest mcweject entry.
Original commit
19:45 stefan search for other commits by this committer
Add entry for exploitable buffer overflow in mcweject.

PR:             111365
Submitted by:   Jeff Forsythe<tornandfilthy2006@yahoo.com>
Original commit
14:36 stefan search for other commits by this committer
Add entry for webcalendar "noSet" variable overwrite vulnerability.

PR:             110585
Submitted by:   Greg Larkin <glarkin@sourcehosting.net>
Original commit
11:16 stefan search for other commits by this committer
Add entry for Zope2 cross-site scripting vulnerability.

Inspired by:    Yasushi Hayashi<yasi@yasi.to> (in PR 111119)
Original commit
Saturday, 31 Mar 2007
16:30 sem search for other commits by this committer
Remove f951cf4a-a1fe-11db-98f9-0004aca3703d entry. It's duplicate to
41da2ba4-a24e-11db-bd24-000f3dcc6a5d.
Original commit
Thursday, 22 Mar 2007
02:27 sat search for other commits by this committer
- Fix versions and dates in latest squid entry

Pointy hat to:  miwi
Original commit
Wednesday, 21 Mar 2007
17:07 remko search for other commits by this committer
Standarise the latest Squid entry.
Original commit
13:04 miwi search for other commits by this committer
- Add entry for squid  TRACE method handling denial of service
Original commit
Friday, 16 Mar 2007
16:57 simon search for other commits by this committer
Fix range for sql-ledger entry which I missed in my original review.
Original commit
11:48 lth search for other commits by this committer
Document sql-ledger vulnerability

PR:             ports/110350
Submitted by:   Antoine Beaupre <anarcat@koumbit.org>
Original commit
07:35 remko search for other commits by this committer
Document cacti -- remote injection exploit

PR:             ports/107838
Submitted by:   Dan Langille <dan at langille dot org>
Original commit
07:31 remko search for other commits by this committer
Correct two tdiary entries:

o correct the affected version numbers
o package name of www/tdiary-devel is "tdiary-devel", not "tdiary"
o add ja-tdiary and ja-tdiary-devel to affected packages

PR:             ports/109086
Submitted by:   KOMATSU Shinichiro <koma2 at lovepeers dot org>
Original commit
07:28 remko search for other commits by this committer
Document two long forgotten Samba vulnerabilities.

PR:             ports/109049
Submitted by:   KOMATSU Shinichiro <koma2 at lovepeers dot org>
Original commit
Wednesday, 14 Mar 2007
23:00 markus search for other commits by this committer
ktorrent -- multiple vulnerabilities:
- Add CVE references
- Bump modification date
Original commit
Monday, 12 Mar 2007
08:39 remko search for other commits by this committer
Spell out multiple vulnerabilities instead of specifying the exact
amount (we always do that). Also bump the modification date for
this entry and the PHP entry that had been touched
Original commit
01:16 markus search for other commits by this committer
Fix typo in PHP entry
Original commit
01:11 markus search for other commits by this committer
Document ktorrent -- two vulnerabilities
Original commit
Saturday, 10 Mar 2007
02:19 kuriyama search for other commits by this committer
Add ja-trac-*.
Original commit
Friday, 9 Mar 2007
15:52 miwi search for other commits by this committer
- fix typo
Original commit
15:48 miwi search for other commits by this committer
- Add entry for mplayer -- DMO File Parsing Buffer Overflow Vulnerability

Reviewed by:    simon (secteam)
Original commit
14:34 miwi search for other commits by this committer
- Add entry for Trac "download wiki page as text" Cross-Site Scripting
Vulnerability.

Reviewed by:    simon@
Original commit
Tuesday, 6 Mar 2007
07:18 simon search for other commits by this committer
Correct affected versions in "mod_jk -- long URL stack overflow
vulnerability" entry.

Noticed by:     Nick Barkas
Original commit
Monday, 5 Mar 2007
23:17 simon search for other commits by this committer
Document mod_jk -- long URL stack overflow vulnerability.
Original commit
Thursday, 1 Mar 2007
18:34 simon search for other commits by this committer
For recent "mozilla -- multiple vulnerabilities" entry:

- Mark Seamonkey 1.1.1 as safe.  While mozilla.org does not clearly
  state this, it does seem to be the case. [1]
- Add another critical vulnerability which wasn't on the web site when
  the vuxml entry was initially added.

Reported by:    Volodymyr Kostyrko [1]
Original commit
Tuesday, 27 Feb 2007
20:10 remko search for other commits by this committer
Document bind -- Multiple Denial of Service vulnerabilities
Now all Security Advisories are merged again in VuXML.
Original commit
20:00 remko search for other commits by this committer
Document FreeBSD -- Jail rc.d script privilege escalation
Original commit
19:50 remko search for other commits by this committer
Document: gtar -- name mangling symlink vulnerability
Original commit
19:46 remko search for other commits by this committer
Document FreeBSD -- Kernel memory disclosure in firewire(4).
Original commit
Monday, 26 Feb 2007
21:08 remko search for other commits by this committer
Document libarchive -- Infinite loop in corrupt archives handling in
libarchive.

This is also FreeBSD SA-06:24.libarchive, FreeBSD systems are not
affected, only specific STABLE versions which are not released!!
Original commit
20:24 remko search for other commits by this committer
Document FreeBSD SA 06:23 OpenSSL - Multiple problems in crypto (3).
Original commit
Sunday, 25 Feb 2007
21:27 simon search for other commits by this committer
- Bump modified date for last update in mozilla entry.
- Bump file copyright year.
Original commit
21:16 ahze search for other commits by this committer
Extend the latest gecko vulnerabilities to mail/lightning.
Original commit
Saturday, 24 Feb 2007
18:50 simon search for other commits by this committer
Fix whitespace which I forgot before committing the last update.
Original commit
18:30 simon search for other commits by this committer
Document mozilla -- multiple vulnerabilities.

Note that Seamonkey 1.1 is marked vulnerable under the "better safe than
sorry" principle, since it's not yet clear if Seamonkey 1.1 is
vulnerable to this batch of vulnerabilities.
Original commit
Wednesday, 21 Feb 2007
22:17 simon search for other commits by this committer
Document snort -- DCE/RPC preprocessor vulnerability.
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54 | 55  »  [Last Page]