notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Newsfeed changes

The news feed page[s] were not laid out well. Two pages, disjointed information, hard to figure out how to use the optional parameters...

Thankfully, someone told me.

The new page is ready for your review. Please compare these two:

You may also be interested in the Github issue.
non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58  »  [Last Page]

Monday, 10 Jul 2006
22:38 simon search for other commits by this committer
Document samba -- memory exhaustion DoS in smbd.
Original commit
11:48 simon search for other commits by this committer
- For the latest trac entry include information from the release
  announcements about setups which are not affected.  To avoid having
  to reference two documents simply reference the release notes for
  all the information (it's basically the same as the changelog with
  slightly different wording).
- Add a modified date tag.
Original commit
08:56 simon search for other commits by this committer
Document twiki -- multiple file extensions file upload vulnerability.
Original commit
08:39 simon search for other commits by this committer
Improve markup for last entry.  No content change.
Original commit
Sunday, 9 Jul 2006
23:31 kuriyama search for other commits by this committer
Add trac DoS.
Original commit
Wednesday, 5 Jul 2006
17:45 thierry search for other commits by this committer
Add an entry for Horde's latest vulnerabilities.
Original commit
17:30 simon search for other commits by this committer
Document mambo -- SQL injection vulnerabilities.
Original commit
Monday, 3 Jul 2006
12:45 miwi search for other commits by this committer
 Document phpmyadmin -- cross site scripting vulnerability

Approved by:    markus (co mentor)
Original commit
Sunday, 2 Jul 2006
13:09 remko search for other commits by this committer
Document webmin, usermin -- arbitrary file disclosure vulnerability.

Details are unknown, all sources talk about an "unspecified" vulnerability.
Original commit
Saturday, 1 Jul 2006
12:19 shaun search for other commits by this committer
Document mutt -- Remote Buffer Overflow Vulnerability.

Approved by:    ahze (mentor)
Original commit
Friday, 30 Jun 2006
22:48 miwi search for other commits by this committer
Document joomla --  multiple vulnerabilities

Approved by:    markus (co mentor)
Original commit
Tuesday, 27 Jun 2006
19:55 remko search for other commits by this committer
Document hashcash -- heap overflow vulnerability.
Original commit
Sunday, 25 Jun 2006
18:39 simon search for other commits by this committer
Document gnupg -- user id integer overflow vulnerability.
Original commit
Friday, 23 Jun 2006
08:32 simon search for other commits by this committer
Document opera -- JPEG processing integer overflow vulnerability.
Original commit
Saturday, 17 Jun 2006
14:36 remko search for other commits by this committer
Update the webcalendar entry, use alphabetic sorting, no functional
change of information.
Original commit
07:11 thierry search for other commits by this committer
Add an entry for Horde's latest XSS vulnerabilities.
Original commit
Friday, 16 Jun 2006
22:38 simon search for other commits by this committer
Add webcalendar -- information disclosure vulnerability.

PR:             ports/98993
Submitted by:   Gregory C. Larkin <glarkin@sourcehosting.net>
Original commit
Wednesday, 14 Jun 2006
16:30 remko search for other commits by this committer
Add FreeBSD-SA-06:17.sendmail to the VuXML database.
Original commit
Monday, 12 Jun 2006
15:41 remko search for other commits by this committer
Bump modification date in the last entry and earn my own pointyhat.

Forgotten by/pointyhat:         remko
Original commit
15:26 remko search for other commits by this committer
Fix the latest entry by using the entity for &, this passes make validate.

Reported by:    Michal Kaps <michal at ionic dot co dot uk>
Pointyhat by:   aaron, (tobez implicit)
Original commit
06:22 aaron search for other commits by this committer
- Added multiple dokuwiki vulnerabilities

Approved by:    tobez
Original commit
Sunday, 11 Jun 2006
12:55 nobutaka search for other commits by this committer
Add an entry for libxine -- buffer overflow vulnerability.
Original commit
Friday, 9 Jun 2006
13:32 remko search for other commits by this committer
Document FreeBSD-SA-06:15.ypserv and FreeBSD-SA-06:16.smbfs.
Add the proper freebsdsa tag for older entries and bump
their modification date.
Original commit
Thursday, 8 Jun 2006
17:10 remko search for other commits by this committer
Document two freeradius issues, one newer and one older issue:
freeradius -- multiple vulnerabilities
freeradius -- authentication bypass vulnerability
Original commit
12:21 ehaupt search for other commits by this committer
Mark graphics/fractorama 1.6.7_1 "clean". This port now links against libtiff
from ports.

Approved by:    simon (secteam)
Original commit
Wednesday, 7 Jun 2006
18:51 simon search for other commits by this committer
The awstats port has PORTEPOCH bumped, so update the vuxml entry awstats
-- arbitrary command execution vulnerability to reflect that.
Original commit
Tuesday, 6 Jun 2006
10:55 simon search for other commits by this committer
Mark squirrelmail-1.4.6_1 as fixed for squirrelmail -- plugin.php
local file inclusion vulnerability.
Original commit
Monday, 5 Jun 2006
20:18 simon search for other commits by this committer
Document squirrelmail -- plugin.php local file inclusion vulnerability.
Original commit
19:57 simon search for other commits by this committer
Document dokuwiki -- spellchecker remote PHP code execution.
Original commit
19:48 simon search for other commits by this committer
Document drupal -- multiple vulnerabilities.
Original commit
Thursday, 1 Jun 2006
18:30 mnag search for other commits by this committer
- Add last two MySQL vulnerabilities

MySQL -- SQL-injection security vulnerability
MySQL -- Information Disclosure and Buffer Overflow Vulnerabilities
Original commit
Tuesday, 23 May 2006
19:23 simon search for other commits by this committer
Document frontpage -- cross site scripting vulnerability and point
FORBIDDEN from the frontpage ports at it.

While this is "only" a cross site scripting vulnerability it has some
rather serious implications which can allow an attacker to take over a
web site, so I'm keeping FORBIDDEN.
Original commit
15:20 mnag search for other commits by this committer
cscope -- buffer overflow vulnerabilities
Original commit
Monday, 22 May 2006
15:25 mnag search for other commits by this committer
coppermine -- Multiple File Extensions Vulnerability
coppermine -- "file" Local File Inclusion Vulnerability
coppermine -- File Inclusion Vulnerabilities
Original commit
Sunday, 21 May 2006
01:02 mnag search for other commits by this committer
phpmyadmin -- XSRF vulnerabilities
Original commit
Thursday, 18 May 2006
21:19 pav search for other commits by this committer
- Normalize the topic of last entry

Requested by:   remko
Original commit
16:12 pav search for other commits by this committer
- Add VuXML entry for vnc 4.1.1
Original commit
Sunday, 14 May 2006
03:57 mnag search for other commits by this committer
- Add vulnerabilities in last topic.
Original commit
03:56 mnag search for other commits by this committer
phpldapadmin -- Cross-Site Scripting and Script Insertion
Original commit
Thursday, 11 May 2006
19:17 tobez search for other commits by this committer
Modify the entry for p5-DBI insecure temporary files creation to reflect
the fact that version 1.37_1 of p5-DBI-137 is OK now.

Reviewed by:    simon
Original commit
Saturday, 6 May 2006
10:56 kuriyama search for other commits by this committer
Add www/fswiki vulnerability.
Original commit
Friday, 5 May 2006
22:24 simon search for other commits by this committer
- Add missing s in latest awstats entry's title.
- Document mysql50-server -- COM_TABLE_DUMP arbitrary code execution.
Original commit
21:39 mnag search for other commits by this committer
- Cancel last rsync entry. Does not affect FreeBSD port.

Notified by:    simon, pav
Discussed with: simon
Original commit
20:45 simon search for other commits by this committer
Document awstat -- arbitrary command execution vulnerability.

Fix a incorrect use of cvename in the latest firefox entry, which I
missed when reviewing the entry (and which make validate did not / can
not catch).
Original commit
Wednesday, 3 May 2006
20:14 mnag search for other commits by this committer
phpwebftp -- "language" Local File Inclusion
Original commit
08:00 vd search for other commits by this committer
Document firefox -- denial of service vulnerability

Reviewed by:    simon
Original commit
01:01 mnag search for other commits by this committer
trac -- Wiki Macro Script Insertion Vulnerability
Original commit
00:56 mnag search for other commits by this committer
rsync -- "xattrs.diff" Patch Integer Overflow Vulnerability
Original commit
00:45 mnag search for other commits by this committer
clamav -- Freshclam HTTP Header Buffer Overflow Vulnerability
Original commit
Monday, 1 May 2006
15:09 mnag search for other commits by this committer
- Add last jabberd entry:

jabberd -- SASL Negotiation Denial of Service Vulnerability
Original commit
Thursday, 27 Apr 2006
11:12 simon search for other commits by this committer
Also mark linux-seamonkey vulnerable to recent mozilla
vulnerabilities.

Reported by:    Andrew Pantyukhin infofarmer at gmail dotty com
Original commit
04:30 mnag search for other commits by this committer
cacti -- ADOdb "server.php" Insecure Test Script Security Issue
Original commit
03:48 mnag search for other commits by this committer
amaya -- Attribute Value Buffer Overflow Vulnerabilities
Original commit
03:22 mnag search for other commits by this committer
lifetype -- ADOdb "server.php" Insecure Test Script Security Issue
Original commit
02:46 mnag search for other commits by this committer
ethereal -- Multiple Protocol Dissector Vulnerabilities
Original commit
Tuesday, 25 Apr 2006
20:57 remko search for other commits by this committer
My 100th commit to the vuln.xml file:

- Document Asterisk -- denial of service vulnerability, local system access.
Original commit
17:40 anholt search for other commits by this committer
Change paraview checks to be < 2.4.3 now that paraview uses system libtiff.
Original commit
Sunday, 23 Apr 2006
21:46 remko search for other commits by this committer
Document zgv, xzgv -- heap overflow vulnerability.
Original commit
14:14 remko search for other commits by this committer
Document crossfire-server -- denial of service and remote code execution
vulnerability.
Original commit
10:25 remko search for other commits by this committer
Document p5-DBI -- insecure temporary file creation vulnerability.
Original commit
09:58 remko search for other commits by this committer
Document wordpress -- full path disclosure.
Original commit
09:35 remko search for other commits by this committer
Document xine -- multiple remote string vulnerabilities.
Original commit
Friday, 21 Apr 2006
16:51 ume search for other commits by this committer
Add an entry for cyrus-sasl -- DIGEST-MD5 Pre-Authentication
Denial of Service.
Original commit
Wednesday, 19 Apr 2006
17:53 remko search for other commits by this committer
Also mark all other versions of FreeBSD (That were released) as
vulnerable.

Noticed by:     brueffer
Discussed with: brueffer, simon
Original commit
17:36 remko search for other commits by this committer
Add FreeBSD -- FPU information disclosure (SA-06:14) to the
vuxml list.
Original commit
Tuesday, 18 Apr 2006
19:39 simon search for other commits by this committer
Add some CERT references to latest Mozilla entry.
Original commit
13:48 mnag search for other commits by this committer
plone -- "member_id" Parameter Portrait Manipulation Vulnerability
Original commit
Sunday, 16 Apr 2006
22:02 simon search for other commits by this committer
Fix copy/paste error in last commit and mark linux-mozilla < 1.7.13 as
vulnerable.
Original commit
21:52 simon search for other commits by this committer
Document mozilla/firefox/thunderbirds's latest attempt at Internet
Explorer compatibility.

Note that I omitted marking some really old mozilla versions as
vulnerable this time, since there is already a bunch of entries
covering these versions (which haven't been in ports for a while).
Original commit
13:00 ehaupt search for other commits by this committer
Update entry for sysutils/heartbeat. The insecure temporary file creation
vulnerability is fixed in 1.2.4.

Approved by:    secteam (simon)
Original commit
01:52 mnag search for other commits by this committer
mailman -- Private Archive Script Cross-Site Scripting
Original commit
Monday, 10 Apr 2006
19:11 remko search for other commits by this committer
Document f2c -- insecure temporary files.

It is not very clear to me to see what version is fixed.  The one fixing
this port should import the latest available one which is fixed.
Original commit
Saturday, 8 Apr 2006
14:53 mnag search for other commits by this committer
mplayer -- Multiple integer overflows
Original commit
Friday, 7 Apr 2006
14:15 mnag search for other commits by this committer
- Add Secunia references for last phpMyAdmin issue.
Original commit
11:23 remko search for other commits by this committer
Document kaffeine -- buffer overflow vulnerability.
Original commit
10:38 remko search for other commits by this committer
Document thunderbird -- javascript execution.
Original commit
Thursday, 6 Apr 2006
17:30 remko search for other commits by this committer
Update the latest zoo entry to match the latest update to the port.
This will mark zoo-2.10.1_2 and later as not vulnerable for this
issue.
Original commit
16:44 mnag search for other commits by this committer
phpmyadmin -- XSS vulnerabilities
phpmyadmin -- 'set_theme' Cross-Site Scripting
Original commit
15:30 mnag search for other commits by this committer
clamav -- Multiple Vulnerabilities
Original commit
04:47 remko search for other commits by this committer
Add cvename to the recent OpenVPN entry.

Submitted by:   Matthias Andree <matthias dot andree at gmx dot de>
Original commit
Wednesday, 5 Apr 2006
20:00 remko search for other commits by this committer
Document mediawiki -- hardcoded placeholder string security bypass
vulnerability.
Original commit
19:50 remko search for other commits by this committer
Document netpbm -- buffer overflow in pnmtopng.
Original commit
19:23 remko search for other commits by this committer
Document zoo -- stack based buffer overflow.
Original commit
19:02 remko search for other commits by this committer
Document mediawiki -- cross site scripting vulnerability.
Original commit
17:37 mnag search for other commits by this committer
dia -- XFig Import Plugin Buffer Overflow
Original commit
14:57 mnag search for other commits by this committer
openvpn -- LD_PRELOAD code execution on client through malicious or compromised
server

PR:             95343
Submitted by:   Matthias Andree <matthias.andree__gmx.de>
Original commit
04:33 mnag search for other commits by this committer
samba -- Exposure of machine account credentials in winbind log files
Original commit
03:46 brooks search for other commits by this committer
Upgrade pubcookie from 3.3.0-beta2 to 3.3.0a fixing serious XSS
vulnerabilities.
Original commit
Saturday, 1 Apr 2006
05:01 edwin search for other commits by this committer
Fill in the version numbers for the vids
6e3b12e2-6ce3-11da-b90c-000e0c2e438a and
82a41084-6ce7-11da-b90c-000e0c2e438a to show which Mantis versions
are vulnerable.

Submitted by:   In cooperation with dvl
Original commit
Thursday, 30 Mar 2006
06:53 simon search for other commits by this committer
For horde -- remote code execution vulnerability in the help viewer
entry:
- Add more references.
- Reformat description to follow normal formatting style better.
- Remove a redundant line in the description to make the meaning more
  clear.
Original commit
Wednesday, 29 Mar 2006
19:08 mnag search for other commits by this committer
freeradius -- EAP-MSCHAPv2 Authentication Bypass
Original commit
Tuesday, 28 Mar 2006
18:13 thierry search for other commits by this committer
Add an entry about Horde's remote code execution vulnerability in the
help viewer.
Original commit
Monday, 27 Mar 2006
19:06 mnag search for other commits by this committer
linux-realplayer -- buffer overrun
linux-realplayer -- heap overflow

Reviewed by:    simon
Original commit
Friday, 24 Mar 2006
18:02 remko search for other commits by this committer
s/8 spaces/tab/ in the sendmail entry.

Noticed by:     simon
Original commit
17:10 remko search for other commits by this committer
Record that our sendmail port was also vulnerable.
Bump modification date.
Original commit
13:08 remko search for other commits by this committer
Update the 'Evolution - remote format string vulnerabilities' entry.
Original commit
12:25 remko search for other commits by this committer
Document the latest three FreeBSD Security Advisories:

SA-06:13
SA-06:12
SA-06:11
Original commit
Tuesday, 21 Mar 2006
17:05 lesi search for other commits by this committer
xorg-server -- privilege escalation

Reviewed by:    simon
Original commit
Monday, 20 Mar 2006
15:21 mnag search for other commits by this committer
- heimdal -- Multiple vulnerabilities

Reviewed by:    simon
Original commit
12:58 vd search for other commits by this committer
Document ftp/curl's TFTP packet buffer overflow vulnerability

Reworked by:    simon
Approved by:    security-officer (simon)
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  48 | 49 | 50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58  »  [Last Page]