notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Newsfeed changes

The news feed page[s] were not laid out well. Two pages, disjointed information, hard to figure out how to use the optional parameters...

Thankfully, someone told me.

The new page is ready for your review. Please compare these two:

You may also be interested in the Github issue.
non port: security/vuxml/vuln.xml

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63  »  [Last Page]

Tuesday, 22 Feb 2005
19:27 nectar search for other commits by this committer
Nit:
- In most recent `unace' entry, replace HTML entity with the Unicode
  character.  We do not use HTML entities so that a VuXML document may
  be processed without using the DTD.  (We also avoid character entity
  references for more natural grep'ing, sed'ing, and editor searching.)

Corrections:
- An invalid UUID was assigned to a FreeRADIUS vulnerability, and went
  undetected since last October.  (>_<)   Correct it.
- A bnc vulnerability was duplicated.  Cancel the older, less informative
  entry and update the newer entry.
Original commit
15:37 naddy search for other commits by this committer
Document unace-1.2b vulnerabilities: buffer overflows, directory traversal.
Original commit
Sunday, 20 Feb 2005
20:51 simon search for other commits by this committer
For the the recent kdelibs entry; note that dcopidlng is only used at
build time.

Reported by:    lofi
Original commit
18:53 simon search for other commits by this committer
Document heap corruption vulnerabilities in putty.
Original commit
Saturday, 19 Feb 2005
12:49 simon search for other commits by this committer
Update affected versions of latest postgresql entry now that the ports
have been fixed.
Original commit
Friday, 18 Feb 2005
22:37 simon search for other commits by this committer
Document insecure temporary file creation in kdelibs.
Original commit
21:55 simon search for other commits by this committer
Document format string vulnerability in bidwatcher.
Original commit
20:37 simon search for other commits by this committer
Document a directory traversal vulnerability in gftp.
Original commit
20:14 simon search for other commits by this committer
- Document two Opera vulnerabilities.
- Update information about fixed version for Opera with regard to
  "Window Injection" issues (based on release notes for Opera 7.54u2).
Original commit
Thursday, 17 Feb 2005
21:45 simon search for other commits by this committer
Document multiple buffer overflows in postgresql.
Original commit
Wednesday, 16 Feb 2005
23:39 simon search for other commits by this committer
Fix entry date for last commit.
Original commit
23:25 simon search for other commits by this committer
Document vulnerabilities in awstats.  Note that this entry will most
likely be updated soon when more information becomes available.
Original commit
Tuesday, 15 Feb 2005
20:55 simon search for other commits by this committer
Add a few more references to the awstats entry.
Original commit
Monday, 14 Feb 2005
15:44 nobutaka search for other commits by this committer
Change affected packages version for the emacs movemail format string
vulnerability since I fixed editors/emacs port by adding a patch
instead of upgrading it to 21.4.
Original commit
00:10 simon search for other commits by this committer
Document DoS in powerdns.
Original commit
Sunday, 13 Feb 2005
23:19 simon search for other commits by this committer
Document format string vulnerability in the Emacs movemail utility.
Original commit
11:28 danfe search for other commits by this committer
- Reflect fixing vulnerability in `net/opendchub'
- Print project's name correctly
Original commit
09:59 simon search for other commits by this committer
- Fix a cvename that should have been a certvu.
- Delete trailing white space.
- Fix some nearby formatting while I'm here anyway.
Original commit
09:21 simon search for other commits by this committer
Document two vulnerabilities in ngircd.
Original commit
Saturday, 12 Feb 2005
23:53 simon search for other commits by this committer
Document mod_python information leakage vulnerability.
Original commit
20:40 simon search for other commits by this committer
Document mailman directory traversal vulnerability.
Original commit
Friday, 11 Feb 2005
23:29 nectar search for other commits by this committer
Expand HTML entity reference in latest VuXML entry.
Original commit
21:59 naddy search for other commits by this committer
Document enscript-{a4,letter,letterdj} vulnerabilities.
Original commit
13:37 danfe search for other commits by this committer
Vulnerability in unrtf is fixed now.
Original commit
Tuesday, 8 Feb 2005
21:33 simon search for other commits by this committer
Document privilege escalation vulnerability in postgresql.
Original commit
18:14 simon search for other commits by this committer
Document multiple protocol dissectors vulnerabilities in ethereal.
Original commit
14:49 nectar search for other commits by this committer
Add another squid issue.

PR:             ports/76967
Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
14:43 nectar search for other commits by this committer
Add CERT Vulnerability Note reference for one squid issue,
and correct the reference for another one [1].

Reported by:    Thomas-Martin Seck <tmseck@netcologne.de> [1]
Original commit
13:48 nectar search for other commits by this committer
Add CVE name for squid confusing empty ACL issue.
Original commit
Monday, 7 Feb 2005
20:02 nectar search for other commits by this committer
Add US-CERT Vulnerability Note references for recent squid issues.
Original commit
Friday, 4 Feb 2005
04:26 perky search for other commits by this committer
Add missing <code> markups in a citation from PSF-2005-001.
Original commit
04:09 perky search for other commits by this committer
Add an entry for PSF-2005-001,
"SimpleXMLRPCServer.py allows unrestricted traversal"
Original commit
Thursday, 3 Feb 2005
22:30 marcus search for other commits by this committer
Update the entry for CAN-2005-0064 to indicate that gpdf 2.8.3 has a fix
for this vulnerability.
Original commit
Wednesday, 2 Feb 2005
18:59 nectar search for other commits by this committer
Note that perl does not have a suidperl by default.
Original commit
17:38 nectar search for other commits by this committer
Note vulnerabilities in perl.
Original commit
15:46 nectar search for other commits by this committer
Add Bugtraq ID for evolution issue.
Original commit
Tuesday, 1 Feb 2005
17:03 nectar search for other commits by this committer
Add CVE name for squid WCCP issue.
Original commit
14:14 nectar search for other commits by this committer
Add a <modified> tag to the perl File::Path issue since the affected
versions were changed.

Forgotten by: tobez
Original commit
13:38 tobez search for other commits by this committer
Narrow perl File::Path vulnerability version range a bit.
Original commit
09:03 niels search for other commits by this committer
Documented vulnerabilities found in the newspost, newsfetch and newsgrab ports.

http://people.freebsd.org/~niels/issues/newspost-20050114.txt
http://people.freebsd.org/~niels/issues/newsgrab-20050114.txt
http://people.freebsd.org/~niels/issues/newsfetch-20050119.txt

Approved by:    nectar (mentor)
Original commit
Monday, 31 Jan 2005
21:44 nectar search for other commits by this committer
The latest xpdf buffer overflow has been repaired in an update
to pdftohtml.

Submitted by:   erwin
Original commit
21:40 nectar search for other commits by this committer
Add CVE names for recent squid vulnerabilities.
Original commit
Saturday, 29 Jan 2005
21:43 sem search for other commits by this committer
squid -- buffer overflow in WCCP recvfrom() call

PR:             ports/76827
Submitted by:   squid maintainer
Original commit
Thursday, 27 Jan 2005
16:38 simon search for other commits by this committer
Mark cups-base as fixed wrt. to "makeFileKey2() buffer overflow
vulnerability".
Original commit
Wednesday, 26 Jan 2005
20:25 simon search for other commits by this committer
Document "makeFileKey2()" buffer overflow vulnerability in xpdf (and
programs embedding xpdf).
Original commit
16:20 nectar search for other commits by this committer
pdflib has been corrected.

Noticed by:     Hilko Meyer <Hilko.Meyer@gmx.de>
Original commit
Tuesday, 25 Jan 2005
13:50 nectar search for other commits by this committer
Document a vulnerability in zhcon.
Original commit
10:51 simon search for other commits by this committer
Fix last YAMT entry update to actually make sense... Greater than and
less than are not the same...

Pointy hat to:  simon
Original commit
10:46 simon search for other commits by this committer
Mark latest YAMT port version as fixed.
Original commit
00:50 simon search for other commits by this committer
Document arbitrary code execution vulnerability in evolution.
Original commit
Monday, 24 Jan 2005
22:25 nectar search for other commits by this committer
The previous commit was

Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
22:24 nectar search for other commits by this committer
Correct the entry date for 4e4bd2c2-6bd5-11d9-9e1e-c296ac722cb3
``squid -- HTTP response splitting cache pollution attack''.
Original commit
20:12 nectar search for other commits by this committer
Document a local vulnerability in mod_dosevasive.
Original commit
19:39 nectar search for other commits by this committer
Document a possible cache-poisoning issue affecting squid.

Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
18:45 nectar search for other commits by this committer
Document Bugzilla XSS issue.
Original commit
18:38 nectar search for other commits by this committer
Oops, forgot to set <discovery> date.
Original commit
17:35 nectar search for other commits by this committer
Document window injection vulnerabilities affecting several web browsers.
Original commit
15:29 nectar search for other commits by this committer
Cancel duplicate phpbb entry e8c6ade2-6bcc-11d9-8e6f-000a95bc6fae.  It
was already documented as e3cf89f0-53da-11d9-92b7-ceadd4ac2edd.
Useful references and descriptions were merged.

Noticed by:     simon
Original commit
Sunday, 23 Jan 2005
23:52 simon search for other commits by this committer
Document a vulnerability in YAMT.
Original commit
Saturday, 22 Jan 2005
14:37 simon search for other commits by this committer
Add squid security advisories for two recent squid entries.

Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
09:35 edwin search for other commits by this committer
squid bug #1200:

        squid -- HTTP response splitting cache pollution attack

PR:             ports/76550
Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
01:13 simon search for other commits by this committer
Fix typo in last commit.
Original commit
00:55 simon search for other commits by this committer
Document XSS in Horde.
Original commit
Friday, 21 Jan 2005
18:30 nectar search for other commits by this committer
Oops, I accidently changed an <entry> date when I should have
added a <modified> date.
Original commit
17:48 nectar search for other commits by this committer
Document vulnerabilities in older versions of Midnight Commander.
Original commit
17:34 nectar search for other commits by this committer
Document a race condition in Perl's File::Path module.
Original commit
17:01 nectar search for other commits by this committer
Document phpBB vulnerabilities.
Original commit
16:50 nectar search for other commits by this committer
Document vulnerabilities in the Opera web browser's Java implementation.
Original commit
16:38 nectar search for other commits by this committer
Document that older versions of sudo lack CDPATH environmental variable
handling.
Original commit
16:30 nectar search for other commits by this committer
Document vulnerabilities in fcron.
Original commit
16:07 nectar search for other commits by this committer
Document vulnerabilities in RealPlayer.
Original commit
15:54 nectar search for other commits by this committer
Add CVE name and iDEFENSE advisory references to xzgv issue.
Original commit
15:37 nectar search for other commits by this committer
Grr, get the imlib version number right!
Original commit
15:31 nectar search for other commits by this committer
Oops, imlib 1.9.15 is still affected.  Adjust version number to reflect
upcoming fix.
Original commit
15:16 nectar search for other commits by this committer
Document xpm heap overflows and integer overflows affecting imlib and imlib2.
Original commit
14:53 nectar search for other commits by this committer
Document a vulnerability in eGroupWare.
Original commit
14:42 nectar search for other commits by this committer
Document Quake II vulnerabilities reported by Richard Stanway.
Original commit
13:53 nectar search for other commits by this committer
Add CVE names for konversation bugs.
Original commit
Wednesday, 19 Jan 2005
20:47 josef search for other commits by this committer
Document security issue in irc/konversation.

Pointed out by: markus
Original commit
16:39 nectar search for other commits by this committer
Correct several instances where the "msgid" attribute content had an
extraneous trailing greater-than character ">", e.g.

   <mlist msgid="some-message@id>">some-url</mlist>

These were probably the result of off-by-one errors during
cut-and-paste.
Original commit
16:19 nectar search for other commits by this committer
Eliminate character entity references.  They are technically fine of
course, but I prefer to use the UTF-8 character directly: it makes
grep'ing and the like easier.
Original commit
14:13 nectar search for other commits by this committer
Update entries with 12 new CVE name references.
Original commit
11:52 edwin search for other commits by this committer
Fix date (was YYYY-MM-DD, now 2005-01-19)

Thanks for Chimera@#bsdports
Original commit
11:05 edwin search for other commits by this committer
squid -- no sanity check of usernames in squid_ldap_auth

(My first attempt to update this thing. Hope all goes fine!)

PR:             ports/76364
Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
Tuesday, 18 Jan 2005
20:25 simon search for other commits by this committer
Document remote DoS in CUPS.

Heads-ups by:   Hilko Meyer <hilko.meyer@gmx.de>
Description by: nectar
Original commit
17:47 nectar search for other commits by this committer
During last year's bumpercrop of vulnerabilities in libtiff, a 2004 CVE
name was assigned to what was actually a much older (circa March 2002)
denial-of-service issue.  Document it, since occassionally the CVE name
crops up and then I wonder why we missed it.
Original commit
17:23 nectar search for other commits by this committer
Document exploitable vulnerabilities in zgv and xzgv.
Original commit
16:59 nectar search for other commits by this committer
Document bug in Mozilla-based software that may leave downloaded files
or attachments world-readable.
Original commit
16:02 simon search for other commits by this committer
Add more references to exim entry.
Original commit
15:23 nectar search for other commits by this committer
pdflib contains libtiff, and thus is affected by several vulnerabilities
that affected libtiff.
Original commit
12:29 simon search for other commits by this committer
Document remote command execution vulnerability in awstats.
Original commit
01:02 simon search for other commits by this committer
Document security vulnerability in ImageMagick.
Original commit
Monday, 17 Jan 2005
17:44 simon search for other commits by this committer
Update "cups-base -- HPGL buffer overflow vulnerability" entry to
reflect the fix in the latest port version.
Original commit
17:20 nectar search for other commits by this committer
Spelling corrections.
Original commit
13:42 nectar search for other commits by this committer
Regarding CUPS lppasswd entry: Add the CVE names for each issue inline
with the excerpt from Bernstein's message.  Note that the third issue
does not effect users of FreeBSD 4.6 or later.
Original commit
Sunday, 16 Jan 2005
23:15 simon search for other commits by this committer
Document two vulnerabilities in CUPS.

Heads up by:    Hilko Meyer <hilko.meyer@gmx.de>
Original commit
20:46 simon search for other commits by this committer
Document mysqlaccess insecure temporary file creation.
Original commit
18:47 simon search for other commits by this committer
Document buffer overflow vulnerability in unrtf.
Original commit
17:18 simon search for other commits by this committer
Correct recent squid entry: WCCP is in fact enabled by default.

Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de> (squid maintainer)
Original commit
Thursday, 13 Jan 2005
21:22 nectar search for other commits by this committer
For mod_access_referer issue:
- Correct spelling.
- `null' in `null pointer' should not be all caps
- Correct the secunia.com URL (it did not identify this particular bug)
Original commit

Number of commits found: 6273 (showing only 100 on this page)

[First Page]  «  53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63  »  [Last Page]