notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
non port: security/vuxml/vuln.xml

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60  »  [Last Page]

Tuesday, 1 Nov 2005
09:33 sem search for other commits by this committer
- Document skype vulnerabilities
- Document PHP vulnerabilities
- Convert first letters in titles from upcase to lowercase
  in my last additions.
Original commit
08:44 sem search for other commits by this committer
- Document CVE-2005-3258:
    Squid FTP Server Response Handling Denial of Service
Original commit
Monday, 31 Oct 2005
19:03 sem search for other commits by this committer
- Document a BASE Basic Analysis and Security Engine vulnerability
Original commit
18:02 simon search for other commits by this committer
Back out the accidentally committed white-space modification parts of
rev.  1.869, but keep the lynx entry.

Pointy hat to:  naddy
OK'ed by:       naddy
Original commit
09:04 barner search for other commits by this committer
Add entry for "fetchmail -- fetchmailconf local password exposure",
which was fixed with fetchmail-6.2.5.2_1 and above.
Original commit
Sunday, 30 Oct 2005
22:17 naddy search for other commits by this committer
Document lynx remote buffer overflow in NNTP header handling.
Original commit
Thursday, 27 Oct 2005
19:40 sem search for other commits by this committer
- Fix a ruby vulnerabuility in the safe level settings.

Based on:       ports/87816
Submitted by:   Phil Oleson <oz@nixil.net>

Security:      
http://vuxml.FreeBSD.org/1daea60a-4719-11da-b5c6-0004614cc33d.html
Original commit
Wednesday, 26 Oct 2005
19:53 simon search for other commits by this committer
Add more references to entry net-snmp -- remote DoS vulnerability.
Original commit
10:00 simon search for other commits by this committer
- Mark linux-firefox 1.0.7 as fixed
  wrt. 8665ebb9-2237-11da-978e-0001020eed82 (Mozilla/firefox IDN buffer
  overflow) [1].
- Correct some of the the earlier linux-firefox entries to match
  versions before 1.0.7, not after (whoops)...

Prodded by:     Andrew P. <infofarmer@gmail.com> [1]
Original commit
Tuesday, 25 Oct 2005
19:52 lesi search for other commits by this committer
Add misc/compat5x to "openssl -- potential SSL 2.0 rollback".

Reviewed by:    simon
Original commit
Sunday, 23 Oct 2005
17:10 simon search for other commits by this committer
Also mark xli as vulnerable to xloadimage -- buffer overflows in NIFF
image title handling, and latest port version as fixed.

Reported by:    jkoshy
Original commit
16:50 simon search for other commits by this committer
For entry libgadu -- multiple vulnerabilities:

- Mark latest centericq port version as fixed.
- Fix cite in description.
Original commit
09:09 simon search for other commits by this committer
For entry zope28 -- expose RestructuredText functionality to untrusted
users:

- Do not match zope 2.7.8 which has been fixed. [1]
- Fix typo in topic.
- Add another reference.

Reported by:    Gerhard Schmidt <estartu augusta de> [1]
Original commit
Saturday, 22 Oct 2005
13:41 simon search for other commits by this committer
Add another reference to clamav -- arbitrary code execution and DoS
vulnerabilities entry.
Original commit
Thursday, 20 Oct 2005
13:52 naddy search for other commits by this committer
Document x11/xloadimage buffer overflows in NIFF image title handling.
Original commit
Wednesday, 19 Oct 2005
18:17 nectar search for other commits by this committer
Rename all CAN-yyyy-nnnn to CVE-yyyy-nnnn, with the exception of text
inside <blockquote>s.
See <URL:http://www.cve.mitre.org/cve/renumber.html>.
Original commit
Tuesday, 18 Oct 2005
19:45 simon search for other commits by this committer
For entry: snort -- Back Orifice preprocessor buffer overflow vulnerability:
- Sort references.
- Add ISS advisory to references.
Original commit
17:42 simon search for other commits by this committer
- Document snort -- Back Orifice preprocessor buffer overflow vulnerability.
- Use standard topic format for webcalendar entry.
- Fix package name in webcalendar so it matches the actual package
  name.
Original commit
Friday, 14 Oct 2005
21:57 sem search for other commits by this committer
- Document www/webcalendar vulnerability.
Original commit
21:38 sem search for other commits by this committer
- Document www/gallery2 vulnerability.
Original commit
Wednesday, 12 Oct 2005
22:53 simon search for other commits by this committer
Improve last couple of entries:
- Use standard topic format.
- Fix packagename in phpmyadmin and zone entries.
- Fix indention and remove EOL white-space.
- Make lead in a bit more verbose.
- Add more references to phpmyadmin issue.
- Remove some redundant quoted text in zope issue.
Original commit
14:51 mnag search for other commits by this committer
Add entry for openssl
Remove entry about safe mode in phpmyadmin
Original commit
00:24 mnag search for other commits by this committer
Add entry for phpmyadmin (PMASA-2005-4)
Original commit
00:12 mnag search for other commits by this committer
Fix typo with range values
Original commit
00:01 mnag search for other commits by this committer
Add entry from zope28
Original commit
Sunday, 9 Oct 2005
21:03 simon search for other commits by this committer
For libxine -- format string vulnerability entry:
- Add reference to xine security announcement.
- Fix indention on a few lines.
Original commit
16:14 nobutaka search for other commits by this committer
Add an entry for libxine format string vulnerability.
Original commit
10:14 simon search for other commits by this committer
Mark older revisions linux_base-suse 9.3 as vulnerable to kdebase --
Kate backup file permission leak.
Original commit
Friday, 7 Oct 2005
07:31 sergei search for other commits by this committer
- Mark cfengine's arbitrary file overwriting vulnerability as fixed in 2.1.6_1
- Add another possible variant of package name - cfengine2
Original commit
Wednesday, 5 Oct 2005
17:44 thierry search for other commits by this committer
Add an entry for UW-IMAP Mailbox Name Handling Remote Buffer Overflow
Vulnerability (CAN-2005-2933).
Original commit
15:55 ehaupt search for other commits by this committer
Add credit for recent ftp/weex incident

Approved by:    novel (mentor)
Original commit
Tuesday, 4 Oct 2005
13:23 garga search for other commits by this committer
rinetd >= 0.62_1 has no more vulnerabilities
Original commit
Sunday, 2 Oct 2005
20:10 remko search for other commits by this committer
Add references to three squid entries.

Submitted by:           Thomas-Martin Seck <tmseck at netcologne dot de>
                        (except for the bid's which i added myself).
Original commit
17:46 simon search for other commits by this committer
Use the <freebsdpr> tag to markup a PR in weex -- remote format string
vulnerability entry.
Original commit
16:11 jylefort search for other commits by this committer
Document a format string vulnerability in ftp/weex.
Original commit
07:45 simon search for other commits by this committer
Document picasm -- buffer overflow vulnerability.
Original commit
Saturday, 1 Oct 2005
16:43 nobutaka search for other commits by this committer
Add an URL to the entry of the japanese/uim.
Original commit
16:35 nobutaka search for other commits by this committer
Document japanese/uim privilege escalation vulnerability.
Original commit
15:21 simon search for other commits by this committer
Document cfengine -- arbitrary file overwriting vulnerability.
Original commit
10:17 remko search for other commits by this committer
Mark zsync <= 0.4.1 vulnerable to the zlib buffer overflow vulnerability.

Inspired by:            gordon's commit
Original commit
08:40 simon search for other commits by this committer
Add more references to unace -- multiple vulnerabilities entry.
Original commit
07:14 simon search for other commits by this committer
Add CVE name to an older ProZilla entry.
Original commit
Thursday, 29 Sep 2005
20:01 simon search for other commits by this committer
Add more references for latest phpmyfaq entry.
Original commit
19:31 simon search for other commits by this committer
- Add a note that new entries, per convention, should be added to the
  start of this file.

For latest phpmyfaq entry:

- Use port directory name as first part of topic.
- No need to include information about affected releases in topic
  (it's somewhat redundant and makes the title longer).
- Reindent body with standard FreeBSD Doc Project (more or less)
  style.
Original commit
Wednesday, 28 Sep 2005
22:54 vsevolod search for other commits by this committer
Document vulnerabilities in www/phpmyfaq
Original commit
Saturday, 24 Sep 2005
09:22 remko search for other commits by this committer
Add linux_base-suse-9.3 to the zlib entry.

Inspired by:            trevors commit.
Original commit
08:31 simon search for other commits by this committer
Document clamav -- arbitrary code execution and DoS vulnerabilities.
Original commit
Friday, 23 Sep 2005
21:44 simon search for other commits by this committer
- Be consistent and call entries "firefox & mozilla", not the other way
  around.
- Mark latest linux-mozilla port as fixed for recent mozilla
  vulnerabilities.
Original commit
19:19 simon search for other commits by this committer
- Document mozilla & firefox -- multiple vulnerabilities.
- Add Mozilla Foundation Security Advisory references to two other
  firefox/mozilla entries.
Original commit
Wednesday, 21 Sep 2005
23:03 simon search for other commits by this committer
Add real references to urban -- stack overflow vulnerabilities.
Original commit
22:31 simon search for other commits by this committer
Document mozilla & firefox -- command line URL shell command injection.
Original commit
21:59 simon search for other commits by this committer
Add CVE name for tor -- diffie-hellman handshake flaw.
Original commit
21:46 simon search for other commits by this committer
Correct package name for entry bind -- buffer overrun vulnerability.
Original commit
21:15 simon search for other commits by this committer
Add CVE name to an older CUPS issue.
Original commit
Monday, 19 Sep 2005
16:12 remko search for other commits by this committer
Fix the htdig entry, the port version and the VuXML version did not
align.

Reported by:            Nic Bellamy <nic at bellamy dot co dot nz>
Original commit
16:09 remko search for other commits by this committer
Fix the squirrelmail entry since only versions prior to 1.4.5 were
affected. Bump modification date accordingly.

Reported by:            Avinash Piare <avinash at piare dot org>
Original commit
Saturday, 17 Sep 2005
19:08 remko search for other commits by this committer
Document the following items:

o apache -- Certificate Revocation List (CRL) off-by-one vulnerability
o squirrelmail -- _$POST variable handling allows for various attacks

Reviewed by:            simon
Original commit
Thursday, 15 Sep 2005
20:14 pav search for other commits by this committer
- Add an entry on possible DOS condition regarding NTLM in squid

PR:             ports/86179
Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
Wednesday, 14 Sep 2005
22:22 lesi search for other commits by this committer
Document X11 server -- pixmap allocation vulnerability.

Reviewed by:    simon
Original commit
Tuesday, 13 Sep 2005
20:18 remko search for other commits by this committer
Document unzip -- permission race vulnerability. [1]

Update the recent htdig entry with it's corrected version.

Reviewed by:            simon [1]
Original commit
Saturday, 10 Sep 2005
20:55 simon search for other commits by this committer
Document firefox & mozilla -- buffer overflow vulnerability.

Prodded by:     pav
Original commit
Wednesday, 7 Sep 2005
08:46 lawrance search for other commits by this committer
Mark the latest version of cups-base fixed for "xpdf -- disk fill DoS
vulnerability"
Original commit
Sunday, 4 Sep 2005
15:24 remko search for other commits by this committer
Add forgotten </package> line.

Spotted by:             simon
Original commit
15:16 remko search for other commits by this committer
Mark b2evolution prior to 0.9.0.12_2 vulnerable to the XML_RPC remote php code
injection vulnerability.

Inspired by:            pav's commit, updating the port.
Original commit
09:03 remko search for other commits by this committer
Document htdig -- cross site scripting vulnerability.

Reviewed by:    simon
Original commit
07:54 sem search for other commits by this committer
- Document two squid security related issues.

PR:             ports/85688
Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de> (squid maintainer)
Original commit
Saturday, 3 Sep 2005
19:05 remko search for other commits by this committer
Document bind9 -- denial of service.
Also merge the FreeBSD-SA-05:12.bind9 advisory in the entry. [1]

Suggested by:           simon [1]
Reviewed by:            simon
Original commit
18:06 remko search for other commits by this committer
Document bind -- buffer overrun vulnerability
Original commit
Friday, 2 Sep 2005
13:10 simon search for other commits by this committer
Add a more or less bogus reference section to the last entry, to make it
a valid entry.  The reference simply references the VuXML entry itself,
but at least it fixes the build for now.

Missed by:      simon
Original commit
12:59 jylefort search for other commits by this committer
Document stack overflow vulnerabilities in games/urban.

Approved by:    simon
Original commit
Monday, 29 Aug 2005
20:47 simon search for other commits by this committer
Mark latest evolution port version as fixed wrt. evolution -- remote
format string vulnerabilities.
Original commit
15:10 kuriyama search for other commits by this committer
Add entry for fswiki's vuln.
Original commit
08:11 niels search for other commits by this committer
Dante 1.1.15 is no longer affected by the fd_set bitmap index overflow.
Updated the version in VuXML (was 0).

Approved by:    nectar (mentor)
Original commit
Sunday, 28 Aug 2005
20:48 simon search for other commits by this committer
- Fill out part of the std. VuXML template missed in the last entry.
- Mark acroread 7.0.1 as fixed for acroread -- XML External Entity
  vulnerability. [1]

Reported by:    Sverre H. Huseby [1]
Original commit
Saturday, 27 Aug 2005
22:25 simon search for other commits by this committer
Document evolution -- remote format string vulnerabilities.

Approved by:    portmgr (blanket, VuXML)
Original commit
21:54 simon search for other commits by this committer
Document pam_ldap -- authentication bypass vulnerability.

Approved by:    portmgr (blanket, VuXML)
Original commit
18:17 simon search for other commits by this committer
Mark phpgroupware as vulnerable to pear-XML_RPC -- remote PHP code
injection vulnerability.

Reported by:    olgeni
Approved by:    portmgr (blanket, VuXML)
Original commit
Friday, 26 Aug 2005
21:24 simon search for other commits by this committer
Document pcre -- regular expression buffer overflow.

Approved by:    portmgr (blanket, VuXML)
Original commit
Tuesday, 23 Aug 2005
20:26 simon search for other commits by this committer
Mark latest awstats port as fixed for awstats -- arbitrary code
execution vulnerability.

Approved by:    portmgr (blanket, VuXML)
Original commit
19:07 sem search for other commits by this committer
Document mail/elm remote buffer overflow vulnerability.

PR:             ports/85225
Submitted by:   Kevin Day <toasty@dragondata.com> (elm maintainer)
Approved by:    portmgr (blanket, VuXML)
Original commit
Friday, 19 Aug 2005
09:58 remko search for other commits by this committer
Document four vulnerabilities in openvpn:

* openvpn -- multiple TCP clients connecting with the same certificate at the
same time can crash the server
* openvpn -- denial of service: malicious authenticated &quot;tap&quot; client
can deplete server virtual memory
* openvpn -- denial of service: undecryptable packet from authorized client can
disconnect unrelated clients
* openvpn -- denial of service: client certificate validation can disconnect
unrelated clients

Approved by:    portsmgr (blanket VuXML)
Submitted by:   Matthias Andree <matthias dot andree at gmx dot de>
Original commit
Wednesday, 17 Aug 2005
20:01 simon search for other commits by this committer
Also mark phpAdsNew as affected by "pear-XML_RPC -- remote PHP code
injection vulnerability".

Approved by:    portmgr (blanket, VuXML)
Original commit
19:46 remko search for other commits by this committer
Add the fixed version so that people do not get a stale portaudit when the
update is there.
Also fix some indentation that i overlooked.

Noticed by:             simon (both of the items)
Approved by:            portsmgr (blanket VuXML)
Original commit
19:34 remko search for other commits by this committer
Document tor -- diffie-hellman handshake flaw.

Submitted by:           Michal Bartkowiak <michal at nonspace dot net>
Approved by:            portsmgr (blanket VuXML)
Original commit
Tuesday, 16 Aug 2005
21:19 simon search for other commits by this committer
gpdf has been fixed for "xpdf -- disk fill DoS vulnerability", mark it
as such.

Approved by:    portmgr (blanket, VuXML)
Original commit
20:56 simon search for other commits by this committer
Add eGroupWare to the list of packages affected by "pear-XML_RPC --
remote PHP code injection vulnerability".

Approved by:    portmgr (blanket, VuXML)
Original commit
18:43 simon search for other commits by this committer
Document acroread -- plug-in buffer overflow vulnerability.

Approved by:    portmgr (blanket, VuXML)
Original commit
Monday, 15 Aug 2005
20:38 simon search for other commits by this committer
Add phpmyfaq and drupal to the "pear-XML_RPC -- remote PHP code
injection vulnerability" entry since they contain an embedded version of
pear-XML_RPC.

Fix typo in body of the latest xpdf entry (note: no modified date bump
as this is a minor typo fix which does change <affects>).

Approved by:    portmgr (blanket, VuXML)
Original commit
13:20 simon search for other commits by this committer
Document pear-XML_RPC -- remote PHP code injection vulnerability.

Submitted by:   hrs
Approved by:    portmgr (blanket, VuXML)
Original commit
Sunday, 14 Aug 2005
21:09 simon search for other commits by this committer
Document awstats -- arbitrary code execution vulnerability.

Approved by:    portmgr (blanket, VuXML)
Original commit
Friday, 12 Aug 2005
16:38 simon search for other commits by this committer
After further examination it turns out that gnugadu does not include
libgadu, at least not any in any current version, and from looking at
the gnugadu code there is no direct indication that this code should
actually be vulnerable to the other libgadu vulnerabilities. [1]

The gaim part of libgadu -- multiple vulnerabilities was fixed in
1.4.0_1. [2]

Polish translation clue:        pjd [1]
General clue by:                markus [2]
Not enough checking:            simon
Approved by:                    portmgr (blanket, VuXML)
Original commit
14:45 simon search for other commits by this committer
Remove pl-gnugadu2 and kadu from being affected by libgadu -- multiple
vulnerabilities, since it turns out that they use libgadu from the ekg
port.

Approved by:    portmgr (blanket, VuXML)
Original commit
14:21 simon search for other commits by this committer
Document libgadu -- multiple vulnerabilities.

Approved by:    portmgr (blanket, VuXML)
Original commit
11:26 simon search for other commits by this committer
Document gaim -- AIM/ICQ away message buffer overflow and gaim --
AIM/ICQ non-UTF-8 filename crash.

Approved by:    portmgr (blanket, VuXML)
Original commit
10:42 simon search for other commits by this committer
Remove pdftohtml from the list of packages affected by xpdf -- disk
fill DoS vulnerability, since it includes xpdf 2, which should not be
affected.

Approved by:    portmgr (blanket, VuXML)
Original commit
Thursday, 11 Aug 2005
22:18 simon search for other commits by this committer
Document xpdf -- disk fill DoS vulnerability.

Approved by:    portmgr (blanket, VuXML)
Original commit
12:40 simon search for other commits by this committer
Mark apache 1.3.33_2 as fixed for apache -- http request smuggling.

Approved by:    portmgr (blanket, VuXML)
Original commit
Tuesday, 9 Aug 2005
11:51 simon search for other commits by this committer
Document gforge -- XSS and email flood vulnerabilities.

Approved by:    portmgr (blanket, VuXML)
Original commit
Sunday, 7 Aug 2005
22:19 simon search for other commits by this committer
Document postnuke -- multiple vulnerabilities.

Approved by:    portmgr (blanket, VuXML)
Original commit
Friday, 5 Aug 2005
13:32 simon search for other commits by this committer
Document mambo -- multiple vulnerabilities.

Approved by:    portmgr (blanket, VuXML)
Original commit

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  50 | 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60  »  [Last Page]