notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
This referral link gives you 10% off a Fastmail.com account and gives me a discount on my Fastmail account.

Get notified when packages are built

A new feature has been added. FreshPorts already tracks package built by the FreeBSD project. This information is displayed on each port page. You can now get an email when FreshPorts notices a new package is available for something on one of your watch lists. However, you must opt into that. Click on Report Subscriptions on the right, and New Package Notification box, and click on Update.

Finally, under Watch Lists, click on ABI Package Subscriptions to select your ABI (e.g. FreeBSD:14:amd64) & package set (latest/quarterly) combination for a given watch list. This is what FreshPorts will look for.

non port: security/vuxml/vuln.xml

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62  »  [Last Page]

Wednesday, 1 Jun 2005
15:53 nectar search for other commits by this committer
correct version number for mailman password generation issue
Original commit
15:51 nectar search for other commits by this committer
Document vulnerability in set-user-ID sympa application.
Original commit
15:36 nectar search for other commits by this committer
Another older mailman vulnerability, somewhat minor
Original commit
15:27 nectar search for other commits by this committer
Add year-old mailman vulnerability, that seems to not have been
previously documented here.
Original commit
14:48 nectar search for other commits by this committer
document Apache Jakarta Tomcat 5.x XSS issue
Original commit
Sunday, 29 May 2005
15:01 simon search for other commits by this committer
Mark samba-2.2.12.j1.0beta1_2 as safe from "samba -- integer overflow
vulnerability".

Reminded by:    NAKAJI Hiroyuki <nakaji@jp.freebsd.org>
Original commit
03:06 kuriyama search for other commits by this committer
- Update to 3.5.8 (including XSS problem fix).

Submitted by:   Toshiya SAITOH <toshiya@saitoh.nu>
PR:             ports/81520
Original commit
Sunday, 22 May 2005
13:27 remko search for other commits by this committer
Remove a forgotten :.

Spotted by:             simon
Original commit
13:18 remko search for other commits by this committer
Document the following issues:

o freeradius -- sql injection and denial of service vulnerability
o ppxp -- local root exploit
o oops -- format string vulnerability

Approved by:    simon
Original commit
Thursday, 19 May 2005
19:56 simon search for other commits by this committer
Fix entry dates for latest squid entries.
Original commit
19:48 remko search for other commits by this committer
Reword the cdrdao entry, this includes comments from Simon which i overlooked.

Forgotten by:   remko
Spotted by:     simon
Original commit
14:17 pav search for other commits by this committer
- Update Squid to 2.5.STABLE10

PR:             ports/81213
Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de> (maintainer)
Original commit
04:17 remko search for other commits by this committer
Document cdrdao -- unspecified privilege escalation vulnerability.

Approved by:            simon
Original commit
Saturday, 14 May 2005
03:43 simon search for other commits by this committer
Document two gaim issues.
Original commit
Friday, 13 May 2005
16:24 nectar search for other commits by this committer
Add FreeBSD-SA-05:09.htt.
Original commit
15:32 nectar search for other commits by this committer
Update some leafnode references.
Add new leafnode vulnerability.

PR:             ports/80724
Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Original commit
Thursday, 12 May 2005
09:59 simon search for other commits by this committer
Document two new vulnerabilities in mozilla/firefox.
Original commit
Wednesday, 11 May 2005
19:00 simon search for other commits by this committer
Document mozilla -- code execution via javascript: IconURL vulnerability.
Original commit
Monday, 9 May 2005
07:04 okazaki search for other commits by this committer
Document some vulnerabilities in groff.
- pic2graph and eqn2graph are vulnerable to symlink attack through temporary
files
- groffer uses temporary files unsafely

PR:             ports/80671
Submitted by:   KOMATSU Shinichiro
Original commit
Tuesday, 3 May 2005
10:14 sem search for other commits by this committer
- gnu-radius exploitation was fixed in maintenance release 1.2.94
  as reported in
http://www.idefense.com/application/poi/display?id=141&type=vulnerabilities

PR:             ports/80558 (follow-up)
Submitted by:   Vsevolod Stakhov <vsevolod@highsecure.ru>
Original commit
Monday, 2 May 2005
18:57 glewis search for other commits by this committer
. Update the version for the jar(1) vulnerability so that 1.2.2p11_4 is
  no longer considered vulnerable.  Adjust the modified date for the entry.
Original commit
Sunday, 1 May 2005
14:33 remko search for other commits by this committer
Document sharutils -- unshar insecure temporary file creation

Approved by:            simon
Original commit
12:25 remko search for other commits by this committer
Document rsnapshot -- local privilege escalation

Approved by:    simon
Original commit
00:30 brooks search for other commits by this committer
coppermine -- IP spoofing and XSS vulnerability
Original commit
Friday, 29 Apr 2005
15:00 glewis search for other commits by this committer
. Correct the range of vulnerable jdk14 ports for the jar(1) vulnerability
  and update the modified time for the entry.
Original commit
Wednesday, 27 Apr 2005
21:35 simon search for other commits by this committer
Document ImageMagick -- ReadPNMImage() heap overflow vulnerability.
Original commit
21:24 simon search for other commits by this committer
Bump modified date for last commit.
Original commit
20:46 glewis search for other commits by this committer
. Adjust ranges so that jdk-1.3.1p9_5 is no longer marked as vulnerable to
  the jar(1) vulnerability but is still marked vulnerable to the browser
  plugin vulnerability (although the plugin is no longer built by default).
Original commit
Monday, 25 Apr 2005
21:53 simon search for other commits by this committer
Document mplayer & libxine -- MMS and Real RTSP buffer overflow
vulnerabilities.
Original commit
21:10 simon search for other commits by this committer
Document some older vulnerabilities in GAIM.
Original commit
Saturday, 23 Apr 2005
11:40 simon search for other commits by this committer
Document kdewebdev -- kommander untrusted code execution vulnerability.
Original commit
Friday, 22 Apr 2005
21:53 remko search for other commits by this committer
Fix a typo in the kdelibs - kimgio entry.
Original commit
21:52 remko search for other commits by this committer
junkbuster -- heap corruption vulnerability and configuration modification
vulnerability

Approved by:            simon
Original commit
08:22 simon search for other commits by this committer
Document kdelibs -- kimgio input validation errors.
Original commit
Tuesday, 19 Apr 2005
22:09 simon search for other commits by this committer
Mark latest openoffice 1.1 as fixed wrt. openoffice -- DOC document
heap overflow vulnerability.

Informed by:    maho
Original commit
11:14 remko search for other commits by this committer
Document gld -- format string and buffer overflow vulnerabilities
Original commit
Sunday, 17 Apr 2005
15:34 naddy search for other commits by this committer
Document remote buffer overflow in ftp/axel.
Original commit
Saturday, 16 Apr 2005
22:52 simon search for other commits by this committer
Document firefox -- PLUGINSPAGE privileged javascript execution (also
from the < 1.0.3 batch).
Original commit
22:35 remko search for other commits by this committer
Document jdk - jar directory traversal vulnerability.

Approved by:    simon
Original commit
16:12 simon search for other commits by this committer
Document several mozilla/firefox issues.
Original commit
Friday, 15 Apr 2005
21:47 simon search for other commits by this committer
Mark wget >= 1.10.a1 safe from the "wget -- multiple vulnerabilities"
entry.

Info provided by:       sf
Original commit
Wednesday, 13 Apr 2005
23:17 simon search for other commits by this committer
Document openoffice -- DOC document heap overflow vulnerability.
Original commit
Tuesday, 12 Apr 2005
08:24 simon search for other commits by this committer
Fix and document insecure temporary file handling in portupgrade.

Security:       CAN-2005-0610
Security:      
http://vuxml.FreeBSD.org/22f00553-a09d-11d9-a788-0001020eed82.html
Approved by:    erwin (mentor), maintainer timeout
OK'ed by:       portmgr
Reviewed by:    nectar
Original commit
Sunday, 10 Apr 2005
19:41 simon search for other commits by this committer
Document three GAIM vulnerabilities.
Original commit
18:47 simon search for other commits by this committer
Document an old PHP issue.
Original commit
10:22 simon search for other commits by this committer
Document squid -- DoS on failed PUT/POST requests vulnerability.

Submitted by:   Devon H. O'Dell <dodell@offmyserver.com> (original version)
Original commit
Saturday, 9 Apr 2005
20:42 pav search for other commits by this committer
- Fix closing tag on the entry I just touched.

Pointed out by: still Chimera
Blaming:        too much bear earlier tonight
Original commit
20:38 pav search for other commits by this committer
- Add <modified> to the entry I just touched

Prodded by:     Chimera
Original commit
20:21 pav search for other commits by this committer
- CAN-2005-0133 is fixed in clamav-devel-20050408

PR:             ports/79688
Submitted by:   Renato Botelho <freebsd@galle.com.br>
Original commit
Tuesday, 5 Apr 2005
20:57 simon search for other commits by this committer
Bump modified date for entry modified last commit.
Original commit
20:03 ume search for other commits by this committer
add CVE name to latest vuln of Cyrus IMAPd.
Original commit
19:57 thierry search for other commits by this committer
Add an entry for a XSS vulnerabilty fixed in horde-3.0.4.
Original commit
Monday, 4 Apr 2005
20:06 simon search for other commits by this committer
Document wu-ftpd -- remote globbing DoS vulnerability.
Original commit
Sunday, 3 Apr 2005
06:53 simon search for other commits by this committer
Add CVE name to hashash entry.
Original commit
Saturday, 2 Apr 2005
23:15 naddy search for other commits by this committer
Document hashcash format string vulnerability.
Original commit
Saturday, 26 Mar 2005
20:49 simon search for other commits by this committer
Document clamav -- zip handling DoS vulnerability.

Approved by:    portmgr (blanket, VuXML)
Original commit
Thursday, 24 Mar 2005
14:15 nectar search for other commits by this committer
Document Wine information disclosure.

Based on an entry that was
Submitted by:   Devon H. O'Dell <dodell@offmyserver.com>
Approved by:    portmgr (blanket, VuXML)
Original commit
14:08 nectar search for other commits by this committer
Document the most serious of the recently disclosed
Mozilla/Firefox/Thunderbird vulnerabilities.

Based on entries that were
Submitted by:   Devon H. O'Dell <dodell@offmyserver.com>
Approved by:    portmgr (blanket, VuXML)
Original commit
Wednesday, 23 Mar 2005
18:29 nectar search for other commits by this committer
Document Sylpheed buffer overflow.

Reminded by:    netchild
Approved by:    portmgr (blanket, VuXML)
Original commit
Monday, 21 Mar 2005
21:19 simon search for other commits by this committer
Document xv -- filename handling format string vulnerability.

Approved by:    portmgr (implicit, VuXML)
Original commit
20:27 simon search for other commits by this committer
Document kdelibs -- local DCOP denial of service vulnerability.

Approved by:    portmgr (implicit, VuXML)
Original commit
Friday, 18 Mar 2005
19:16 simon search for other commits by this committer
Mark grip port as fixed for recent vulnerability.

Requested by:   ahze
Original commit
Tuesday, 15 Mar 2005
21:13 simon search for other commits by this committer
Document phpmyadmin -- increased privilege vulnerability.
Original commit
19:40 danfe search for other commits by this committer
Note that recent Quake2-LNX is fixed.
Original commit
14:27 ale search for other commits by this committer
Recent mysql snapshot import fixed several vulnerabilities.
Original commit
Monday, 14 Mar 2005
21:55 simon search for other commits by this committer
Document ethereal -- multiple protocol dissectors vulnerabilities.
Original commit
20:19 simon search for other commits by this committer
Document "grip -- CDDB response multiple matches buffer overflow
vulnerability".
Original commit
19:49 simon search for other commits by this committer
Update references for latest MySQL entry:

- Use bid tag for Bugtraq ID reference.
- Add CVE names.
Original commit
15:16 ale search for other commits by this committer
Document multiple mysql remote vulnerabilities.
Original commit
Sunday, 13 Mar 2005
10:31 thierry search for other commits by this committer
Add an entry about rxvt-unicode bufer overflow.
Original commit
Tuesday, 8 Mar 2005
22:52 simon search for other commits by this committer
Document two phpMyAdmin issues.
Original commit
21:26 simon search for other commits by this committer
Document libexif -- buffer overflow vulnerability.
Original commit
Monday, 7 Mar 2005
15:45 nectar search for other commits by this committer
Fix invalid date.

Noticed by:     Kang Liu <liukang@bjut.edu.cn>
Original commit
Sunday, 6 Mar 2005
17:06 nectar search for other commits by this committer
Add <modified> date for recent commit to phpbb vulnerability.

Forgotten by:   delphij

While here, add msgids for recent phpbb addition.
Original commit
Saturday, 5 Mar 2005
15:53 delphij search for other commits by this committer
Document a low risk HTML injection (configuration bypass)
vulnerability [1] of phpBB.

(maintainer contacted and is preparing a fix)

[1] http://marc.theaimsgroup.com/?l=bugtraq&m=110987231502274
Original commit
15:42 delphij search for other commits by this committer
Add bugtraq bug ID for phpbb vulnerability.

Submitted by:   Kang LIU <liukang bjut edu cn>
Original commit
Friday, 4 Mar 2005
18:14 nectar search for other commits by this committer
Document two phpnuke vulnerabilities, and a Linux RealPlayer
vulnerability.

Based on entries that were
Submitted by:   Devon H. O'Dell <dodell@sitetronics.com>
Original commit
Thursday, 3 Mar 2005
22:20 simon search for other commits by this committer
- Document ImageMagick -- format string vulnerability.
- Fix typo on older tiff entry.
Original commit
Wednesday, 2 Mar 2005
13:17 nobutaka search for other commits by this committer
Document the privilege escalation vulnerability in uim.
Original commit
Tuesday, 1 Mar 2005
13:39 nectar search for other commits by this committer
Fix typo in linux-tiff version number for
http://vuxml.freebsd.org/8f86d8b5-6025-11d9-a9e7-0001020eed82.html

Reported by:    Ian Moore <no-spam@swiftdsl.com.au>
Original commit
13:23 nectar search for other commits by this committer
Document lighttpd information disclosure bug.

This entry is based on one that was
Submitted by:   Devon H. O'Dell <dodell@offmyserver.com>
Original commit
Monday, 28 Feb 2005
13:41 nectar search for other commits by this committer
Fix typo in linux-tiff version number for
http://vuxml..freebsd.org/fc7e6a42-6012-11d9-a9e7-0001020eed82.html

Reported by:    Ian Moore <no-spam@swiftdsl.com.au>
Original commit
10:48 delphij search for other commits by this committer
Document latest phpBB critical security vulnerabilities.

Submitted by:   Kang LIU <liukang bjut edu cn>
Original commit
03:42 nectar search for other commits by this committer
Correct the linux-tiff version number for several entries.

Reported by:    netchild
Original commit
Sunday, 27 Feb 2005
21:24 simon search for other commits by this committer
Document curl -- authentication buffer overflow vulnerability.
Original commit
20:34 simon search for other commits by this committer
- Document cyrus-imapd -- multiple buffer overflow vulnerabilities. [1]
- Use bid tag for a reference in sup entry.

Advice from:    ume [1]
Original commit
13:21 hrs search for other commits by this committer
Document format string vulnerabilities in net/sup.
Original commit
Saturday, 26 Feb 2005
21:12 simon search for other commits by this committer
- Just use mozilla in title for last entry for consistency.
- Document mozilla -- insecure temporary directory vulnerability.
Original commit
20:36 simon search for other commits by this committer
Update list of affected mozilla/firefox ports by the web browsers --
window injection vulnerabilities entry.
Original commit
14:25 simon search for other commits by this committer
Document mozilla & firefox -- arbitrary code execution vulnerability.

Submitted by:   Devon H. O'Dell <dodell@sitetronics.com> (original version)
Original commit
Friday, 25 Feb 2005
04:55 nectar search for other commits by this committer
Improve the description of the latest phpBB information disclosure
bugs.

Submitted by:   delphij (in part)
Original commit
Thursday, 24 Feb 2005
15:43 hrs search for other commits by this committer
Document a format string vulnerability in mkbold-mkitalic.

Reviewed by:    simon
Original commit
Wednesday, 23 Feb 2005
16:20 nectar search for other commits by this committer
Add CVE names for wget.
Original commit
15:11 nectar search for other commits by this committer
De-confuse latest AWStats entry: rewrite description, and add relevant
references.  There were so many bugs, it was hard to keep them straight
(^_^).
Original commit
14:37 nectar search for other commits by this committer
Format the <topic> of the most recent entry so that it is more
consistent with other entries.
Original commit
13:13 delphij search for other commits by this committer
Document latest phpbb vulnerabilities.

Discussed with: phpbb maintainer
Original commit
05:15 simon search for other commits by this committer
Add more references to recent putty vulnerability.
Original commit
Tuesday, 22 Feb 2005
21:58 nectar search for other commits by this committer
The mod_dosevasive port was upgraded.
Original commit
19:27 nectar search for other commits by this committer
Nit:
- In most recent `unace' entry, replace HTML entity with the Unicode
  character.  We do not use HTML entities so that a VuXML document may
  be processed without using the DTD.  (We also avoid character entity
  references for more natural grep'ing, sed'ing, and editor searching.)

Corrections:
- An invalid UUID was assigned to a FreeRADIUS vulnerability, and went
  undetected since last October.  (>_<)   Correct it.
- A bnc vulnerability was duplicated.  Cancel the older, less informative
  entry and update the newer entry.
Original commit
15:37 naddy search for other commits by this committer
Document unace-1.2b vulnerabilities: buffer overflows, directory traversal.
Original commit

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  52 | 53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62  »  [Last Page]