notbug ipv6 ready As an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
non port: security/vuxml/vuln.xml

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63  »  [Last Page]

Tuesday, 5 Oct 2004
13:52 nectar search for other commits by this committer
Record another PHP security issue.

Approved by:    portmgr
Original commit
12:52 nectar search for other commits by this committer
Note that xv should not be used.

Approved by:    portmgr
Original commit
Monday, 4 Oct 2004
19:59 nectar search for other commits by this committer
Note a symlink vulnerability in getmail.

Submitted by:   Shane Kinney <mod6@freebsdhackers.net>
Approved by:    portmgr
Original commit
17:30 nectar search for other commits by this committer
Fill in empty topic from previous commit.

Noticed by:     Shane Kinney <mod6@freebsdhackers.net>
Approved by:    portmgr
Original commit
17:09 nectar search for other commits by this committer
Record FreeBSD-SA-04:15.syscons.

Approved by:    portmgr
Original commit
14:01 nectar search for other commits by this committer
Add missing PORTEPOCH for samba.

Noticed by:     dinoex
Approved by:    portmgr
Original commit
Sunday, 3 Oct 2004
22:49 nectar search for other commits by this committer
Note racoon certificate verification bug.

Submitted by:   Jon Passki <cykyc@yahoo.com>
Approved by:    portmgr
Original commit
15:51 nectar search for other commits by this committer
Note distcc IP address ACL bug.

Submitted by:   Jon Passi <cykyc@yahoo.com>
Approved by:    portmgr
Original commit
15:38 nectar search for other commits by this committer
Remove a duplicate entry.

Submitted by:   Jon Passki <cykyc@yahoo.com>
Approved by:    portmgr
Original commit
Friday, 1 Oct 2004
01:40 nectar search for other commits by this committer
Correct the version number for latest Mozilla entry.
(cut-n-paste damage)

Approved by:    portmgr
Original commit
01:37 nectar search for other commits by this committer
Document the last few of the relatively recent Mozilla vulnerabilities.

Approved by:    portmgr
Original commit
Thursday, 30 Sep 2004
23:32 nectar search for other commits by this committer
Correct mangled CVE name: s/8983/0903/

Approved by:    portmgr
Original commit
23:29 nectar search for other commits by this committer
Add another two older vulnerabilities affecting Mozilla & co.
Continue to try hard to cover past package names:
  - I missed el-linux-mozillafirebird previously.
  - Move all the `obsolete' package names into one place
    for clarity.

Approved by:    portmgr
Original commit
22:30 nectar search for other commits by this committer
Don't forget `ja-samba' also.

Approved by:    portmgr
Original commit
22:26 nectar search for other commits by this committer
Note samba file disclosure vulnerability.

Approved by:    portmgr
Original commit
Wednesday, 29 Sep 2004
16:48 trhodes search for other commits by this committer
Fix apache version number entry, bump modified date for apache as well.

Approved by:    portmgr
Original commit
Tuesday, 28 Sep 2004
18:02 nectar search for other commits by this committer
Make an initial attempt at covering all Mozilla/Firefox/Thunderbird
package names that we've had.  Similar changes need to be made to many
other entries, but let's use this one as a test subject first.

Approved by:    portmgr
Original commit
15:06 nectar search for other commits by this committer
Correct spelling of phpnuke package name.

Reported by:    Dan Langille
Approved by:    portmgr
Original commit
14:31 nectar search for other commits by this committer
Note BMP decoder flaws in Mozilla/Firefox/Thunderbird.

Approved by:    portmgr
Original commit
14:28 nectar search for other commits by this committer
Note stack buffer overflow in Mozilla mail.

Approved by:    portmgr
Original commit
14:22 nectar search for other commits by this committer
Document Mozilla/Firefox/Thunderbird heap buffer overflows.

Approved by:    portmgr
Original commit
13:36 nectar search for other commits by this committer
Correct the package name for phpMyAdmin.

Reported by:    Matthew Seaman <m.seaman@infracaninophile.co.uk>
Approved by:    portmgr
Original commit
Monday, 27 Sep 2004
15:15 nectar search for other commits by this committer
Add CERT Vulnerability Note references to xpm entry.

Approved by:    portmgr
Original commit
02:57 nectar search for other commits by this committer
Note two older vulnerabilities in PHP.

Submitted by:   Jon Passki <cykyc@yahoo.com>
Approved by:    portmgr
Original commit
Sunday, 26 Sep 2004
18:17 nectar search for other commits by this committer
Note subversion information disclosure vulnerability.

Submitted by:   lev
Approved by:    portmgr
Original commit
18:04 nectar search for other commits by this committer
Add missing PORTEPOCH in a mozilla entry.
Correct package name in an apache entry.

Reported by:    Dan Langille <dan@langille.org>
Approved by:    portmgr
Original commit
Saturday, 25 Sep 2004
00:59 nectar search for other commits by this committer
Forgot to add <modified> element for last commit.

Approved by:    portmgr
Original commit
00:58 nectar search for other commits by this committer
Add missing PORTEPOCH on one of the mozilla entries.

Noticed by:     Dan Langille <dan@langille.org>
Approved by:    portmgr
Original commit
Thursday, 23 Sep 2004
15:07 nectar search for other commits by this committer
Document vulnerabilities in lha.

Reviewed by:    dinoex
Approved by:    portmgr
Original commit
14:16 nectar search for other commits by this committer
Lately it seems I like to use dashes in topics... but I should at
least be consistent with how many.  s/---/--/

Approved by:    portmgr
Original commit
14:10 nectar search for other commits by this committer
Document mysql buffer overflow.

Reported by:    ale
Approved by:    portmgr
Original commit
Wednesday, 22 Sep 2004
16:39 nectar search for other commits by this committer
Document Mozilla security icon spoofing vulnerability.

Approved by:    portmgr
Original commit
16:16 nectar search for other commits by this committer
Document Mozilla vulnerability involving NULL bytes in FTP URLs.

Also, correct s/firebird/firefox/ in a previously documented issue.

Approved by:    portmgr
Original commit
15:59 nectar search for other commits by this committer
Document Mozilla automatic file upload vulnerability.

Approved by:    portmgr
Original commit
15:44 nectar search for other commits by this committer
Document mozilla certificate import denial-of-service vulnerability.

Approved by:    portmgr
Original commit
Tuesday, 21 Sep 2004
22:04 nectar search for other commits by this committer
Note a file name disclosure issue in rssh.

Reported by:    leeym
Approved by:    portmgr
Original commit
Monday, 20 Sep 2004
20:13 nectar search for other commits by this committer
Add entry describe GNU Radius denial-of-service vulnerability.

Approved by:    portmgr
Original commit
20:06 nectar search for other commits by this committer
Add sudoedit vulnerability.

Approved by:    portmgr
Original commit
Sunday, 19 Sep 2004
23:36 nectar search for other commits by this committer
In latest CVS entry, remove the reference to the exploit.  It does
not apply to any of these vulnerabilities, but to the previous CVS
vulnerability (CAN-2004-0396).

Approved by:    portmgr
Original commit
23:32 nectar search for other commits by this committer
Oh yeah, add affected FreeBSD versions for CVS issues.

Approved by:    portmgr
Original commit
23:23 nectar search for other commits by this committer
Update CVS entry with some details.

Approved by:    portmgr
Original commit
17:38 trhodes search for other commits by this committer
Add an entry for the mod_proxy buffer overflow existant in apache13.

Approved by:    portmgr
Original commit
Saturday, 18 Sep 2004
15:42 nectar search for other commits by this committer
Note some fixes for XPM image decoding vulnerabilities.

Submitted by:   lesi

Add references to Chris Evans's advisories while I'm at it.

Approved by:    portmgr
Original commit
Friday, 17 Sep 2004
02:12 marcus search for other commits by this committer
Update to gdk-pixbuf vulnerability to reflect the fixed version of gtk20.

Approved by:    portmgr( implicit)
Original commit
Wednesday, 15 Sep 2004
19:54 nectar search for other commits by this committer
Note that a patched version of webmin 1.150 is now available, thanks
to olengi@.

Submitted by:   olengi

Add a paragraph introducing the Webmin blockquote while I'm here.

Approved by:    portmgr
Original commit
18:05 nectar search for other commits by this committer
Note gdk-pixbuf image decoding issues.

Approved by:    portmgr
Original commit
17:39 nectar search for other commits by this committer
clement@ has patched Apache 2.

Approved by:    portmgr
Original commit
16:31 nectar search for other commits by this committer
Note CUPS printer queue browser denial-of-service.

Approved by:    portmgr
Original commit
15:57 nectar search for other commits by this committer
Note Apache 2 IPv6 address parsing bug.

Approved by:    portmgr
Original commit
15:16 nectar search for other commits by this committer
Note new libXpm vulnerabilities.

Approved by:    portmgr
Original commit
14:47 nectar search for other commits by this committer
I appear to have deleted a line at the last minute.  Restore it.

Approved by:    portmgr
Original commit
14:45 nectar search for other commits by this committer
Add mod_dav denial-of-service issue.

Approved by:    portmgr
Original commit
14:20 nectar search for other commits by this committer
Oops, forgot to note that the previous issue affects only the Apache 2.x
series.

Approved by:    portmgr
Original commit
14:18 nectar search for other commits by this committer
Add Apache 2 vulnerability concerning environmental variables in
configuration files.

Approved by:    portmgr
Original commit
13:52 nectar search for other commits by this committer
Repair three <freebsdpr> elements.  The content of these elements
must be e.g. "ports/46613", not just "46613".

Reported by:    Matthew Seaman <m.seaman@infracaninophile.co.uk>
Approved by:    portmgr
Original commit
03:03 nectar search for other commits by this committer
Note that some versions of OpenOffice have been corrected.

Approved by:    portmgr
Original commit
Tuesday, 14 Sep 2004
03:38 trhodes search for other commits by this committer
Fix botched date entry and correct iDefense URL.

Approved by:    portmgr
Original commit
03:19 trhodes search for other commits by this committer
Really add Samba 3 vulnerability.
Remove incorrect URL in mpg123 entry.

Approved by:    portmgr
URL noticed:    nectar
Original commit
03:01 trhodes search for other commits by this committer
Correct version.  Note my last commit here was for mpg123 instead of
samba3.

Noticed by:     nectar
Approved by:    portmgr
Original commit
02:21 nectar search for other commits by this committer
- There is a WITHOUT_X11 version of ImageMagick that needs to be
  taken into account.
- Fix transposed characters in `isakmpd'.

Noticed by:     Dan Langille <dan@langille.org>

- Add CVE name reference for ImageMagick.
- Add webmin temporary file handling issue.
- Add OpenOffice temporary file handling issue.
- Widen the `KDE frame injection' issue to cover Mozilla, Firebird,
  Netscape, and Opera as well
- Add Mozilla/Firebird/Netscape SOAPParameter vulnerability
- Add Mozilla/Thunderbird/Netscape POP client vulnerability

Approved by:    portmgr
Original commit
02:02 trhodes search for other commits by this committer
Update for recent Samba3 vulnerabilities.

Approved by:    portmgr
Original commit
Thursday, 2 Sep 2004
12:02 nectar search for other commits by this committer
Adjust the affected version for imlib now that the 2nd instance of BMP
loader has been corrected.
Original commit
Wednesday, 1 Sep 2004
17:12 nectar search for other commits by this committer
The recent commit to the krb5 port brought the version to 1.3.4_1 but
did not correct one of the existing vulnerabilities.  Update the
affected range to compensate.
Original commit
Tuesday, 31 Aug 2004
20:52 nectar search for other commits by this committer
Note recent MIT Kerberos 5 vulnerabilities.
Original commit
14:55 nectar search for other commits by this committer
Document imlib2 BMP decoder bug.
Original commit
14:34 nectar search for other commits by this committer
Document BMP decoder bugs in imlib1 and ImageMagick.
Original commit
Monday, 30 Aug 2004
14:23 nectar search for other commits by this committer
Correct bogus date in mysql entry. (It should be YYYY-MM-DD, not
DD-MM-YYYY.)

Reported by:    robert@openbsd.org
Original commit
14:21 nectar search for other commits by this committer
Add more references (particularly CVE names) for issues affecting
SpamAssassin, tnftpd, ruby, mysql.

Place text taken from another source inside <blockquote cite="...">
for ruby issue.
Original commit
11:08 eik search for other commits by this committer
correct/add some references
Original commit
Friday, 27 Aug 2004
15:29 nectar search for other commits by this committer
Document NSS SSLv2 server buffer overflow (already referenced in
portaudit.txt).
Original commit
14:43 nectar search for other commits by this committer
Document ripMIME decoding bug (already referenced in portaudit.txt).
Original commit
04:29 marcus search for other commits by this committer
Remove <modified/> from the gnomevfs vulnerability since it was the same
as <entry/> and it needed to be last anyway.

Suggested by:   nectar
Original commit
01:48 marcus search for other commits by this committer
Update the gnomevfs entry to reflect the fixed versions.
Original commit
Thursday, 26 Aug 2004
22:30 trhodes search for other commits by this committer
Add entry for moinmoin ACL bypass.
Original commit
22:10 nectar search for other commits by this committer
Note sanitize_path bug in rsync (already referenced in portaudit.txt).
Original commit
21:12 nectar search for other commits by this committer
Unsafe URI handling in gnome-vfs, MidnightCommander.
Original commit
20:34 nectar search for other commits by this committer
Document buffer overflows in SoX (already referenced in portaudit.txt).
Original commit
20:15 nectar search for other commits by this committer
Document cookie bug in Konqueror (already referenced in portaudit.txt).
Original commit
Monday, 23 Aug 2004
19:18 trhodes search for other commits by this committer
Place port name in the description.

Suggested by:   eik
Original commit
16:08 nectar search for other commits by this committer
Add libxine vcd URL handling issue.
Original commit
14:51 nectar search for other commits by this committer
Add DoS in SpamAssassin.
Original commit
13:06 nectar search for other commits by this committer
Add <modified> date for previous commit.
Original commit
13:05 nectar search for other commits by this committer
fidogate-ds was also affected by the ``write files as `news' user''
issue.
Original commit
Sunday, 22 Aug 2004
23:14 nectar search for other commits by this committer
Off-by-one error in courier-imap entry.

Noticed by:     oliver
Original commit
22:58 nectar search for other commits by this committer
Add a more useful reference for the Qt issue.
Original commit
22:56 nectar search for other commits by this committer
Add Qt heap overflow issue.
Original commit
22:39 nectar search for other commits by this committer
Add a security issue affected courier-imap when run with certain debug
flags.
Original commit
22:28 nectar search for other commits by this committer
Add fidogate issue.
Original commit
22:07 nectar search for other commits by this committer
Add an issue covering a vulnerability in mysqlhotcopy.

Reported by:    robert@openbsd.org
Original commit
21:44 nectar search for other commits by this committer
Cancel a VuXML entry for an Apache vulnerability that does not affect
FreeBSD.

Reminded by:    recent conversations :-)
Original commit
Saturday, 21 Aug 2004
08:29 eik search for other commits by this committer
cancelled 6fd9a1e9-efd3-11d8-9837-000c41e2cdad: does not affect FreeBSD
  <http://docs.FreeBSD.org/cgi/mid.cgi?20040817123651.GB930>
Original commit
Tuesday, 17 Aug 2004
21:18 nectar search for other commits by this committer
Add a pointer to Przemyslaw Frasunek's advisory.
Original commit
18:30 nectar search for other commits by this committer
For the lukemftpd/tnftpd issue, add a reference to NetBSD security
advisory now that it is available.
Original commit
18:01 nectar search for other commits by this committer
Note a vulnerability in lukemftpd/tnftpd.
Original commit
12:07 eik search for other commits by this committer
multiple CVS vulnerabilities
Original commit
06:46 knu search for other commits by this committer
Correct the version numbers and dates in the last entry.
Original commit
06:40 knu search for other commits by this committer
Add an entry for:
  Ruby insecure file permissions in the CGI session management
Original commit
Monday, 16 Aug 2004
22:38 nectar search for other commits by this committer
Document a setgid "games" security issue in xonix.  Based on a VuXML
entry that was

Submitted by:   robert@OpenBSD.org
Original commit
Sunday, 15 Aug 2004
15:51 nectar search for other commits by this committer
Correct the version number range affected for ja-samba.
Correct the version number range affected for Mozilla 1.8 alphas.

Problem hinted at by:   eik
Original commit
14:31 nectar search for other commits by this committer
Correct the version number range affected for Mozilla 1.8 alphas.

Problem hinted at by:   eik

While I'm here, add a CVE name reference and a couple of other relevant
Bugzilla links.  It is interesting that this security issue was reported
as early as 1999.  Also, replace the text plagiarized from the Secunia
advisory without attribution with a more helpful (maybe?) description of
the issue.
Original commit

Number of commits found: 6274 (showing only 100 on this page)

[First Page]  «  53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63  »  [Last Page]