notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Newsfeed changes

The news feed page[s] were not laid out well. Two pages, disjointed information, hard to figure out how to use the optional parameters...

Thankfully, someone told me.

The new page is ready for your review. Please compare these two:

You may also be interested in the Github issue.
non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61  »  [Last Page]

Friday, 5 Aug 2005
10:21 remko search for other commits by this committer
Document some recent FreeBSD advisories:
o devfs -- ruleset bypass.
o zlib -- buffer overflow vulnerability.
o ipsec -- Incorrect key usage in AES-XCBC-MAC.

Approved by:    portsmgr (blanket VuXML)
Original commit
Thursday, 4 Aug 2005
15:56 remko search for other commits by this committer
Add some more entries to the apache -- http smuggling vulnerability.

PR:             ports/84312
Submitted by:   Dmitry A Grigorovich <odip at bionet dot nsc dot ru>
Approved by:    portsmgr (blanket VuXML)
Original commit
Wednesday, 3 Aug 2005
17:14 simon search for other commits by this committer
Document proftpd -- format string vulnerabilities.

Approved by:    portmgr (blanket, VuXML)
Original commit
16:54 simon search for other commits by this committer
Note that the fix for gnupg -- OpenPGP symmetric encryption
vulnerability in gnupg is not complete (see entry for details).

Discussed with: nectar
Approved by:    portmgr (blanket, VuXML)
Original commit
11:58 simon search for other commits by this committer
Mark p5-Crypt-OpenPGP, pgp, and pgpin as vulnerable to gnupg --
OpenPGP symmetric encryption vulnerability.

Reminded by:    nectar
Approved by:    portmgr (blanket, VuXML)
Original commit
Monday, 1 Aug 2005
18:38 simon search for other commits by this committer
Mark latest gdal version as fixed for all tiff vulnerabilities.
Original commit
07:45 niels search for other commits by this committer
Added nbsmtp format string vulnerability.

Approved by:    nectar (mentor)
Original commit
Sunday, 31 Jul 2005
23:39 simon search for other commits by this committer
Mark latest the linux-tiff and pdflib ports safe from latest tiff
vulnerability.

Thanks to lawrance and netchild for fast fixes.
Original commit
15:00 simon search for other commits by this committer
Document sylpheed -- MIME-encoded file name buffer overflow
vulnerability.
Original commit
13:50 simon search for other commits by this committer
Document phpmyadmin -- cross site scripting vulnerability.
Original commit
13:23 simon search for other commits by this committer
Document gnupg -- OpenPGP symmetric encryption vulnerability.

Note: this is mainly a theoretical vulnerability.
Original commit
11:38 remko search for other commits by this committer
Bump entry date.

Forgotten by:   remko
Spotted by:     simon
Original commit
11:31 remko search for other commits by this committer
Document vim -- vulnerabilities in modeline handling: glob, expand.

Discussed with:         nectar, simon
Original commit
Saturday, 30 Jul 2005
22:20 simon search for other commits by this committer
Document that ekg -- insecure temporary file creation was fixed in
1.6r2,1.

Noted by:       Michal Kalkowski
Original commit
20:20 simon search for other commits by this committer
Add pdflib-perl, fractorama, gdal, iv, ivtools, ja-iv, ja-libimg,
paraview to recent libtiff vulnerabilities since they contain (and
compile) an embedded version of libtiff...
Original commit
15:48 simon search for other commits by this committer
Document tiff -- buffer overflow vulnerability.
Original commit
11:18 simon search for other commits by this committer
- Misc. markup/whitespace fixes.
- Collapse a few package entries from the latest apache entry (still
  matches same package names, is just shorter markup-wise).
- Use standard topic style for jaberd entry.
- Fix entry date for jaberd entry.
Original commit
10:00 vsevolod search for other commits by this committer
Document jabberd vulnerabilities that were fixed by the latest update.

Approved by:    perky (mentor)
Original commit
09:24 simon search for other commits by this committer
Be consistent and use the same title for the latest ethereal
vulnerabilities as used for previous entries.
Original commit
09:13 simon search for other commits by this committer
Document opera -- image dragging vulnerability and opera -- download
dialog spoofing vulnerability.
Original commit
08:26 simon search for other commits by this committer
Document ethereal -- multiple vulnerabilities.
Original commit
Thursday, 28 Jul 2005
08:51 clement search for other commits by this committer
- Fix apache 2.1 range for CAN-2005-2088 entry which prevents apache 2.0 from
  upgrading.

Pointyhat to:   clement, remko
Reviewed by:    erwin
Original commit
04:22 remko search for other commits by this committer
Mark apache+mod_ssl-1.3.33+2.8.22_1 as not vulnerable in the latest Apache
entry.
Original commit
Wednesday, 27 Jul 2005
17:21 remko search for other commits by this committer
There must be an curse. s/il/li/.

Noticed by:     nectar
Original commit
17:01 remko search for other commits by this committer
Update my latest Apache entry to make clear that this only affects certain
installations (when Apache is used as a HTTP proxy in combination with some
web servers). I didn't make that clear in the first commit.

Requested by:           nectar
Discussed with:         clement
Original commit
15:57 remko search for other commits by this committer
Document apache -- http request smuggling.

Requested by:   clement
Glanced at by:  clement
Original commit
Tuesday, 26 Jul 2005
13:32 erwin search for other commits by this committer
Set modified date in entry for previous commit.

Cluebat swung by:       simon
Original commit
10:50 erwin search for other commits by this committer
Note that the fd_set vulnerability in net/bld was fixed in 0.3.3

Prodded by:     garga
Glanced at by:  remko
Original commit
Monday, 25 Jul 2005
15:57 hrs search for other commits by this committer
Document clamav -- multiple remote buffer overflows.
Original commit
Saturday, 23 Jul 2005
09:30 simon search for other commits by this committer
- Document isc-dhcpd -- format string vulnerabilities (older
  vulnerabilty). [1]
- Use standard title format for latest egroupware entry.

Reminded by:    Panagiotis Christias [1]
Original commit
02:03 kuriyama search for other commits by this committer
Add entry for eGroupWare's recent vulnerabilities.
Original commit
Friday, 22 Jul 2005
09:44 barner search for other commits by this committer
Document denial of service attack in fetchmail 6.5.2.1.

Reported by:    Matthias Andree <matthias.andree@gmx.de>
Reviewed by:    simon
Original commit
Thursday, 21 Jul 2005
21:13 simon search for other commits by this committer
Update phppgadmin entry to note that it was fixed in 3.5.4 and add a
few references while here anyway.

Prodded by:     Tobias Roth (I think :-) )
Original commit
16:31 simon search for other commits by this committer
Document dnrd -- remote buffer and stack overflow vulnerabilities.
Original commit
13:38 simon search for other commits by this committer
Fix typo in last commit

Noticed by:     Matthias Andree <matthias.andree@gmx.de>
Original commit
10:56 simon search for other commits by this committer
Add more references to latest fetchmail entry [1] and sort references
while here anyway.

Submitted by:   Matthias Andree <matthias.andree@gmx.de> [1]
Original commit
08:43 trhodes search for other commits by this committer
Document an issue with the LDAP backend provided by PowerDNS.
Original commit
Wednesday, 20 Jul 2005
19:43 simon search for other commits by this committer
Document fetchmail -- remote root/code injection from malicious POP3
server.

Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Original commit
Monday, 18 Jul 2005
20:07 mich search for other commits by this committer
o add kdebase (kate) vulnarability.

Reviewed by:    simon
Original commit
09:54 simon search for other commits by this committer
Add CVE names to recent bugzilla entry.
Original commit
Saturday, 16 Jul 2005
14:38 simon search for other commits by this committer
- Document firefox & mozilla -- multiple vulnerabilities.
- Minor style nit in drupal entry: Use port name (i.e. lower case) as
  first part of the title.
Original commit
11:29 erwin search for other commits by this committer
Add an entry for the drupal vulnerabilities.
Original commit
Friday, 15 Jul 2005
14:35 niels search for other commits by this committer
Fixed incorrect newsfetch and mnogosearch affected package versions

Approved by:    nectar (mentor)
Original commit
Wednesday, 13 Jul 2005
03:04 kuriyama search for other commits by this committer
Markup fixed version of net-snmp problem.
Original commit
Saturday, 9 Jul 2005
20:02 remko search for other commits by this committer
Correct a typo: s/lemote/remote/

Spotted by:     simon
Original commit
19:57 remko search for other commits by this committer
Document the following vulnerabilities:
phpSysInfo -- cross site scripting vulnerability
mysql-server -- insecure temporary file creation
net-snmp -- fixproc insecure temporary file creation
phpbb -- multiple vulnerabilities
shtool -- insecure temporary file creation

Approved by:            simon
Original commit
Friday, 8 Jul 2005
21:36 simon search for other commits by this committer
Document phppgadmin -- "formLanguage" local file inclusion vulnerability.
Original commit
21:17 simon search for other commits by this committer
Document pear-XML_RPC -- information disclosure vulnerabilities.
Original commit
21:03 simon search for other commits by this committer
Document ekg -- insecure temporary file creation.
Original commit
20:29 simon search for other commits by this committer
Document bugzilla -- multiple vulnerabilities.
Original commit
20:04 simon search for other commits by this committer
Document nwclient -- multiple vulnerabilities (old issues).

PR:             ports/82101
Submitted by:   niels
Noticed by:     Derik van Zuetphen <dz@426.ch>
Original commit
Wednesday, 6 Jul 2005
22:46 simon search for other commits by this committer
Add CAN reference to recent phpbb vulnerability.
Original commit
22:25 simon search for other commits by this committer
Document acroread -- insecure temporary file creation.
Original commit
22:14 simon search for other commits by this committer
Document two calmav vulnerabilities.
Original commit
21:34 simon search for other commits by this committer
- Add FreeBSD-SA-05:16.zlib.
- Fix ranges for recent security advisories, a bunch of <le> really
  should have been <lt>.
Original commit
20:45 simon search for other commits by this committer
Document acroread -- buffer overflow vulnerability.
Original commit
Tuesday, 5 Jul 2005
21:13 simon search for other commits by this committer
Document net-snmp -- remote DoS vulnerability.
Original commit
20:33 simon search for other commits by this committer
Document cacti -- multiple vulnerabilities.

Prodded by:     Babak Farrokhi <babak@farrokhi.net>
Original commit
19:01 simon search for other commits by this committer
- Add another reference to bzip2 -- denial of service and permission
  race vulnerabilities.
- Document two cases of wordpress -- multiple vulnerabilities.
Original commit
Sunday, 3 Jul 2005
08:40 hrs search for other commits by this committer
Document the following issues:
 - phpbb -- remote PHP code execution vulnerability
 - pear-XML_RPC -- arbitrary remote code execution
Original commit
08:12 simon search for other commits by this committer
Add certvu reference to kernel -- TCP connection stall denial of service
vulnerability.
Original commit
Wednesday, 29 Jun 2005
23:00 simon search for other commits by this committer
Add FreeBSD-SA-05:13.ipfw, FreeBSD-SA-05:14.bzip2, and
FreeBSD-SA-05:15.tcp.
Original commit
Friday, 24 Jun 2005
20:38 simon search for other commits by this committer
Document ethereal -- multiple protocol dissectors vulnerabilities.
Original commit
10:22 hrs search for other commits by this committer
Document tor -- information disclosure.
Original commit
09:09 hrs search for other commits by this committer
Document linux-realplayer -- RealText parsing heap overflow.
Original commit
Thursday, 23 Jun 2005
06:55 hrs search for other commits by this committer
Document ruby -- arbitrary command execution on XMLRPC server.
Original commit
Tuesday, 21 Jun 2005
09:58 sem search for other commits by this committer
- net/cacti - potential SQL injection and cross site scripting attacks
Original commit
Monday, 20 Jun 2005
22:34 simon search for other commits by this committer
Document three opera issues.
Original commit
20:18 simon search for other commits by this committer
Document sudo -- local race condition vulnerability.
Original commit
19:17 simon search for other commits by this committer
Add another reference to the latest tcpdump issue.
Original commit
19:09 simon search for other commits by this committer
- Add entry for trac -- file upload/download vulnerability.
- Improve the last couple of entries a bit:
  - Whilespace cleanup.
  - Use standard topic format (port name first, then description
    starting with lower case).
  - Make sure SpamAssasin entry also match other 3.0.3 port revisions.
Original commit
07:30 sem search for other commits by this committer
- razor-agents DoS vulnerabilities

PR:             ports/82414
Submitted by:   dawnshade <h-k@mail.ru>
Original commit
Sunday, 19 Jun 2005
04:57 hrs search for other commits by this committer
Fix year in <discovery> and <entry>.

Noticed by:     nectar
Pointy hat to:  hrs
Original commit
Saturday, 18 Jun 2005
17:27 hrs search for other commits by this committer
Document SpamAssassin -- Denial of service vulnerability.
Original commit
17:15 hrs search for other commits by this committer
Document squirrelmail -- Several cross site scripting vulnerabilities.
Original commit
16:54 hrs search for other commits by this committer
Document acroread -- XML External Entity vulnerability.
Original commit
14:49 simon search for other commits by this committer
Use standard topic format for gzip vulnerability.
Original commit
14:32 simon search for other commits by this committer
Document FreeBSD-SA-05:11.gzip.
Original commit
Friday, 17 Jun 2005
23:19 simon search for other commits by this committer
Document SA-05:10.tcpdump.
Original commit
19:12 simon search for other commits by this committer
Document two vulnerabilities in Gaim.
Original commit
18:37 nectar search for other commits by this committer
Document an older, more serious gallery vulnerability.
Original commit
18:30 nectar search for other commits by this committer
Document XSS vulnerabilities in gallery.
Original commit
18:11 nectar search for other commits by this committer
Document KDE kstars vulnerability.
Original commit
17:00 nectar search for other commits by this committer
Document fd_set overruns reported by 3APA3A.
Original commit
Thursday, 9 Jun 2005
08:44 simon search for other commits by this committer
Document leafnode -- denial of service vulnerability.

Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Original commit
Friday, 3 Jun 2005
19:45 nectar search for other commits by this committer
Document a directory traversal issue in older GForge versions.
Original commit
19:29 nectar search for other commits by this committer
Document an authentication bypass vulnerability in imap-uw.
Original commit
19:18 nectar search for other commits by this committer
Document squid denial-of-service vulnerabilities.
Original commit
19:08 nectar search for other commits by this committer
Document a remote denial-of-service vulnerability in racoon.
Original commit
18:24 nectar search for other commits by this committer
Document integer overflows in xli.
Original commit
18:19 nectar search for other commits by this committer
Document arbitrary command execution vulnerabilities in xli and
xloadimage.
Original commit
18:01 nectar search for other commits by this committer
Add new CVE names for yamt entry.
Original commit
17:56 nectar search for other commits by this committer
Correct and improve recent xli entry:
* It actually affected xloadimage and xli
* A slightly better topic than just "buffer overflows"
* More refererences
* Fix the version number for xli... it is still vulnerable as of this
  writing
Original commit
16:26 nectar search for other commits by this committer
Correct recently added yamt entry:
* This is not CAN-2004-1302, which was documented much earlier
* Try to explain the issue
* Add the only public reference to the issue I can find
Original commit
04:48 trhodes search for other commits by this committer
Buffer overflow in xli.
Original commit
02:15 trhodes search for other commits by this committer
Fix breakage I caused.
Original commit
02:09 trhodes search for other commits by this committer
Note buffer overflows and directory transversal issues in audio/ymat.
Original commit
Wednesday, 1 Jun 2005
17:16 nectar search for other commits by this committer
Update entry for FreeStyle Wiki:
* <topic> style: ASCII em-dash "--" for separator
* replace quoted text with more informative excerpt from a Secunia
  advisory
* add CVE name
Original commit
17:07 nectar search for other commits by this committer
Document vulnerabilities in XView library.
Original commit
16:52 nectar search for other commits by this committer
document a vulnerability in xtrlock
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61  »  [Last Page]