notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
non port: security/vuxml/vuln.xml

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61  »  [Last Page]

Friday, 5 Aug 2005
10:34 remko search for other commits by this committer
Correct the ranges for the IPSec advisory and the devfs advisory.
Also correct proper ranges for the zlib advisory.

Approved by:            portsmgr (blanket VuXML)
Original commit
10:21 remko search for other commits by this committer
Document some recent FreeBSD advisories:
o devfs -- ruleset bypass.
o zlib -- buffer overflow vulnerability.
o ipsec -- Incorrect key usage in AES-XCBC-MAC.

Approved by:    portsmgr (blanket VuXML)
Original commit
Thursday, 4 Aug 2005
15:56 remko search for other commits by this committer
Add some more entries to the apache -- http smuggling vulnerability.

PR:             ports/84312
Submitted by:   Dmitry A Grigorovich <odip at bionet dot nsc dot ru>
Approved by:    portsmgr (blanket VuXML)
Original commit
Wednesday, 3 Aug 2005
17:14 simon search for other commits by this committer
Document proftpd -- format string vulnerabilities.

Approved by:    portmgr (blanket, VuXML)
Original commit
16:54 simon search for other commits by this committer
Note that the fix for gnupg -- OpenPGP symmetric encryption
vulnerability in gnupg is not complete (see entry for details).

Discussed with: nectar
Approved by:    portmgr (blanket, VuXML)
Original commit
11:58 simon search for other commits by this committer
Mark p5-Crypt-OpenPGP, pgp, and pgpin as vulnerable to gnupg --
OpenPGP symmetric encryption vulnerability.

Reminded by:    nectar
Approved by:    portmgr (blanket, VuXML)
Original commit
Monday, 1 Aug 2005
18:38 simon search for other commits by this committer
Mark latest gdal version as fixed for all tiff vulnerabilities.
Original commit
07:45 niels search for other commits by this committer
Added nbsmtp format string vulnerability.

Approved by:    nectar (mentor)
Original commit
Sunday, 31 Jul 2005
23:39 simon search for other commits by this committer
Mark latest the linux-tiff and pdflib ports safe from latest tiff
vulnerability.

Thanks to lawrance and netchild for fast fixes.
Original commit
15:00 simon search for other commits by this committer
Document sylpheed -- MIME-encoded file name buffer overflow
vulnerability.
Original commit
13:50 simon search for other commits by this committer
Document phpmyadmin -- cross site scripting vulnerability.
Original commit
13:23 simon search for other commits by this committer
Document gnupg -- OpenPGP symmetric encryption vulnerability.

Note: this is mainly a theoretical vulnerability.
Original commit
11:38 remko search for other commits by this committer
Bump entry date.

Forgotten by:   remko
Spotted by:     simon
Original commit
11:31 remko search for other commits by this committer
Document vim -- vulnerabilities in modeline handling: glob, expand.

Discussed with:         nectar, simon
Original commit
Saturday, 30 Jul 2005
22:20 simon search for other commits by this committer
Document that ekg -- insecure temporary file creation was fixed in
1.6r2,1.

Noted by:       Michal Kalkowski
Original commit
20:20 simon search for other commits by this committer
Add pdflib-perl, fractorama, gdal, iv, ivtools, ja-iv, ja-libimg,
paraview to recent libtiff vulnerabilities since they contain (and
compile) an embedded version of libtiff...
Original commit
15:48 simon search for other commits by this committer
Document tiff -- buffer overflow vulnerability.
Original commit
11:18 simon search for other commits by this committer
- Misc. markup/whitespace fixes.
- Collapse a few package entries from the latest apache entry (still
  matches same package names, is just shorter markup-wise).
- Use standard topic style for jaberd entry.
- Fix entry date for jaberd entry.
Original commit
10:00 vsevolod search for other commits by this committer
Document jabberd vulnerabilities that were fixed by the latest update.

Approved by:    perky (mentor)
Original commit
09:24 simon search for other commits by this committer
Be consistent and use the same title for the latest ethereal
vulnerabilities as used for previous entries.
Original commit
09:13 simon search for other commits by this committer
Document opera -- image dragging vulnerability and opera -- download
dialog spoofing vulnerability.
Original commit
08:26 simon search for other commits by this committer
Document ethereal -- multiple vulnerabilities.
Original commit
Thursday, 28 Jul 2005
08:51 clement search for other commits by this committer
- Fix apache 2.1 range for CAN-2005-2088 entry which prevents apache 2.0 from
  upgrading.

Pointyhat to:   clement, remko
Reviewed by:    erwin
Original commit
04:22 remko search for other commits by this committer
Mark apache+mod_ssl-1.3.33+2.8.22_1 as not vulnerable in the latest Apache
entry.
Original commit
Wednesday, 27 Jul 2005
17:21 remko search for other commits by this committer
There must be an curse. s/il/li/.

Noticed by:     nectar
Original commit
17:01 remko search for other commits by this committer
Update my latest Apache entry to make clear that this only affects certain
installations (when Apache is used as a HTTP proxy in combination with some
web servers). I didn't make that clear in the first commit.

Requested by:           nectar
Discussed with:         clement
Original commit
15:57 remko search for other commits by this committer
Document apache -- http request smuggling.

Requested by:   clement
Glanced at by:  clement
Original commit
Tuesday, 26 Jul 2005
13:32 erwin search for other commits by this committer
Set modified date in entry for previous commit.

Cluebat swung by:       simon
Original commit
10:50 erwin search for other commits by this committer
Note that the fd_set vulnerability in net/bld was fixed in 0.3.3

Prodded by:     garga
Glanced at by:  remko
Original commit
Monday, 25 Jul 2005
15:57 hrs search for other commits by this committer
Document clamav -- multiple remote buffer overflows.
Original commit
Saturday, 23 Jul 2005
09:30 simon search for other commits by this committer
- Document isc-dhcpd -- format string vulnerabilities (older
  vulnerabilty). [1]
- Use standard title format for latest egroupware entry.

Reminded by:    Panagiotis Christias [1]
Original commit
02:03 kuriyama search for other commits by this committer
Add entry for eGroupWare's recent vulnerabilities.
Original commit
Friday, 22 Jul 2005
09:44 barner search for other commits by this committer
Document denial of service attack in fetchmail 6.5.2.1.

Reported by:    Matthias Andree <matthias.andree@gmx.de>
Reviewed by:    simon
Original commit
Thursday, 21 Jul 2005
21:13 simon search for other commits by this committer
Update phppgadmin entry to note that it was fixed in 3.5.4 and add a
few references while here anyway.

Prodded by:     Tobias Roth (I think :-) )
Original commit
16:31 simon search for other commits by this committer
Document dnrd -- remote buffer and stack overflow vulnerabilities.
Original commit
13:38 simon search for other commits by this committer
Fix typo in last commit

Noticed by:     Matthias Andree <matthias.andree@gmx.de>
Original commit
10:56 simon search for other commits by this committer
Add more references to latest fetchmail entry [1] and sort references
while here anyway.

Submitted by:   Matthias Andree <matthias.andree@gmx.de> [1]
Original commit
08:43 trhodes search for other commits by this committer
Document an issue with the LDAP backend provided by PowerDNS.
Original commit
Wednesday, 20 Jul 2005
19:43 simon search for other commits by this committer
Document fetchmail -- remote root/code injection from malicious POP3
server.

Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Original commit
Monday, 18 Jul 2005
20:07 mich search for other commits by this committer
o add kdebase (kate) vulnarability.

Reviewed by:    simon
Original commit
09:54 simon search for other commits by this committer
Add CVE names to recent bugzilla entry.
Original commit
Saturday, 16 Jul 2005
14:38 simon search for other commits by this committer
- Document firefox & mozilla -- multiple vulnerabilities.
- Minor style nit in drupal entry: Use port name (i.e. lower case) as
  first part of the title.
Original commit
11:29 erwin search for other commits by this committer
Add an entry for the drupal vulnerabilities.
Original commit
Friday, 15 Jul 2005
14:35 niels search for other commits by this committer
Fixed incorrect newsfetch and mnogosearch affected package versions

Approved by:    nectar (mentor)
Original commit
Wednesday, 13 Jul 2005
03:04 kuriyama search for other commits by this committer
Markup fixed version of net-snmp problem.
Original commit
Saturday, 9 Jul 2005
20:02 remko search for other commits by this committer
Correct a typo: s/lemote/remote/

Spotted by:     simon
Original commit
19:57 remko search for other commits by this committer
Document the following vulnerabilities:
phpSysInfo -- cross site scripting vulnerability
mysql-server -- insecure temporary file creation
net-snmp -- fixproc insecure temporary file creation
phpbb -- multiple vulnerabilities
shtool -- insecure temporary file creation

Approved by:            simon
Original commit
Friday, 8 Jul 2005
21:36 simon search for other commits by this committer
Document phppgadmin -- "formLanguage" local file inclusion vulnerability.
Original commit
21:17 simon search for other commits by this committer
Document pear-XML_RPC -- information disclosure vulnerabilities.
Original commit
21:03 simon search for other commits by this committer
Document ekg -- insecure temporary file creation.
Original commit
20:29 simon search for other commits by this committer
Document bugzilla -- multiple vulnerabilities.
Original commit
20:04 simon search for other commits by this committer
Document nwclient -- multiple vulnerabilities (old issues).

PR:             ports/82101
Submitted by:   niels
Noticed by:     Derik van Zuetphen <dz@426.ch>
Original commit
Wednesday, 6 Jul 2005
22:46 simon search for other commits by this committer
Add CAN reference to recent phpbb vulnerability.
Original commit
22:25 simon search for other commits by this committer
Document acroread -- insecure temporary file creation.
Original commit
22:14 simon search for other commits by this committer
Document two calmav vulnerabilities.
Original commit
21:34 simon search for other commits by this committer
- Add FreeBSD-SA-05:16.zlib.
- Fix ranges for recent security advisories, a bunch of <le> really
  should have been <lt>.
Original commit
20:45 simon search for other commits by this committer
Document acroread -- buffer overflow vulnerability.
Original commit
Tuesday, 5 Jul 2005
21:13 simon search for other commits by this committer
Document net-snmp -- remote DoS vulnerability.
Original commit
20:33 simon search for other commits by this committer
Document cacti -- multiple vulnerabilities.

Prodded by:     Babak Farrokhi <babak@farrokhi.net>
Original commit
19:01 simon search for other commits by this committer
- Add another reference to bzip2 -- denial of service and permission
  race vulnerabilities.
- Document two cases of wordpress -- multiple vulnerabilities.
Original commit
Sunday, 3 Jul 2005
08:40 hrs search for other commits by this committer
Document the following issues:
 - phpbb -- remote PHP code execution vulnerability
 - pear-XML_RPC -- arbitrary remote code execution
Original commit
08:12 simon search for other commits by this committer
Add certvu reference to kernel -- TCP connection stall denial of service
vulnerability.
Original commit
Wednesday, 29 Jun 2005
23:00 simon search for other commits by this committer
Add FreeBSD-SA-05:13.ipfw, FreeBSD-SA-05:14.bzip2, and
FreeBSD-SA-05:15.tcp.
Original commit
Friday, 24 Jun 2005
20:38 simon search for other commits by this committer
Document ethereal -- multiple protocol dissectors vulnerabilities.
Original commit
10:22 hrs search for other commits by this committer
Document tor -- information disclosure.
Original commit
09:09 hrs search for other commits by this committer
Document linux-realplayer -- RealText parsing heap overflow.
Original commit
Thursday, 23 Jun 2005
06:55 hrs search for other commits by this committer
Document ruby -- arbitrary command execution on XMLRPC server.
Original commit
Tuesday, 21 Jun 2005
09:58 sem search for other commits by this committer
- net/cacti - potential SQL injection and cross site scripting attacks
Original commit
Monday, 20 Jun 2005
22:34 simon search for other commits by this committer
Document three opera issues.
Original commit
20:18 simon search for other commits by this committer
Document sudo -- local race condition vulnerability.
Original commit
19:17 simon search for other commits by this committer
Add another reference to the latest tcpdump issue.
Original commit
19:09 simon search for other commits by this committer
- Add entry for trac -- file upload/download vulnerability.
- Improve the last couple of entries a bit:
  - Whilespace cleanup.
  - Use standard topic format (port name first, then description
    starting with lower case).
  - Make sure SpamAssasin entry also match other 3.0.3 port revisions.
Original commit
07:30 sem search for other commits by this committer
- razor-agents DoS vulnerabilities

PR:             ports/82414
Submitted by:   dawnshade <h-k@mail.ru>
Original commit
Sunday, 19 Jun 2005
04:57 hrs search for other commits by this committer
Fix year in <discovery> and <entry>.

Noticed by:     nectar
Pointy hat to:  hrs
Original commit
Saturday, 18 Jun 2005
17:27 hrs search for other commits by this committer
Document SpamAssassin -- Denial of service vulnerability.
Original commit
17:15 hrs search for other commits by this committer
Document squirrelmail -- Several cross site scripting vulnerabilities.
Original commit
16:54 hrs search for other commits by this committer
Document acroread -- XML External Entity vulnerability.
Original commit
14:49 simon search for other commits by this committer
Use standard topic format for gzip vulnerability.
Original commit
14:32 simon search for other commits by this committer
Document FreeBSD-SA-05:11.gzip.
Original commit
Friday, 17 Jun 2005
23:19 simon search for other commits by this committer
Document SA-05:10.tcpdump.
Original commit
19:12 simon search for other commits by this committer
Document two vulnerabilities in Gaim.
Original commit
18:37 nectar search for other commits by this committer
Document an older, more serious gallery vulnerability.
Original commit
18:30 nectar search for other commits by this committer
Document XSS vulnerabilities in gallery.
Original commit
18:11 nectar search for other commits by this committer
Document KDE kstars vulnerability.
Original commit
17:00 nectar search for other commits by this committer
Document fd_set overruns reported by 3APA3A.
Original commit
Thursday, 9 Jun 2005
08:44 simon search for other commits by this committer
Document leafnode -- denial of service vulnerability.

Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Original commit
Friday, 3 Jun 2005
19:45 nectar search for other commits by this committer
Document a directory traversal issue in older GForge versions.
Original commit
19:29 nectar search for other commits by this committer
Document an authentication bypass vulnerability in imap-uw.
Original commit
19:18 nectar search for other commits by this committer
Document squid denial-of-service vulnerabilities.
Original commit
19:08 nectar search for other commits by this committer
Document a remote denial-of-service vulnerability in racoon.
Original commit
18:24 nectar search for other commits by this committer
Document integer overflows in xli.
Original commit
18:19 nectar search for other commits by this committer
Document arbitrary command execution vulnerabilities in xli and
xloadimage.
Original commit
18:01 nectar search for other commits by this committer
Add new CVE names for yamt entry.
Original commit
17:56 nectar search for other commits by this committer
Correct and improve recent xli entry:
* It actually affected xloadimage and xli
* A slightly better topic than just "buffer overflows"
* More refererences
* Fix the version number for xli... it is still vulnerable as of this
  writing
Original commit
16:26 nectar search for other commits by this committer
Correct recently added yamt entry:
* This is not CAN-2004-1302, which was documented much earlier
* Try to explain the issue
* Add the only public reference to the issue I can find
Original commit
04:48 trhodes search for other commits by this committer
Buffer overflow in xli.
Original commit
02:15 trhodes search for other commits by this committer
Fix breakage I caused.
Original commit
02:09 trhodes search for other commits by this committer
Note buffer overflows and directory transversal issues in audio/ymat.
Original commit
Wednesday, 1 Jun 2005
17:16 nectar search for other commits by this committer
Update entry for FreeStyle Wiki:
* <topic> style: ASCII em-dash "--" for separator
* replace quoted text with more informative excerpt from a Secunia
  advisory
* add CVE name
Original commit
17:07 nectar search for other commits by this committer
Document vulnerabilities in XView library.
Original commit

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61  »  [Last Page]