notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
This referral link gives you 10% off a Fastmail.com account and gives me a discount on my Fastmail account.

Get notified when packages are built

A new feature has been added. FreshPorts already tracks package built by the FreeBSD project. This information is displayed on each port page. You can now get an email when FreshPorts notices a new package is available for something on one of your watch lists. However, you must opt into that. Click on Report Subscriptions on the right, and New Package Notification box, and click on Update.

Finally, under Watch Lists, click on ABI Package Subscriptions to select your ABI (e.g. FreeBSD:14:amd64) & package set (latest/quarterly) combination for a given watch list. This is what FreshPorts will look for.

non port: security/vuxml/vuln.xml

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54  »  [Last Page]

Friday, 9 Nov 2007
10:00 miwi search for other commits by this committer
- Document tikiwiki -- multiple vulnerabilities

Reviewed by:    simon
Approved by:    portmgr (ports-security blanket)
Original commit
07:51 delphij search for other commits by this committer
Document cups-base remote buffer overflow vulnerability.

Approved by:    portmgr (ports-security blanket)
Original commit
Wednesday, 7 Nov 2007
22:03 delphij search for other commits by this committer
Make perl entry to cover perl-threaded as well.

Reported by:    Andy Greenwood <greenwood.andy gmail com>
Approved by:    portmgr (ports-security blanket)
Original commit
Tuesday, 6 Nov 2007
22:19 miwi search for other commits by this committer
- Document perl --  regular expressions unicode data buffer overflow

Reviewed by:    simon/tobez
Approved by:    portmgr (blanket) (ports-security blanket)
Original commit
18:28 delphij search for other commits by this committer
Document pcre arbitrary code execution vulnerability.

Approved by:    portmgr (ports-security blanket)
Original commit
11:03 beech search for other commits by this committer
- perdition entry - correct range

Approved by:    portmgr (pav) linimon (mentor)
Original commit
09:58 beech search for other commits by this committer
- Add entry for mail/perdition

PR:             ports/117796
Approved by:    portmgr (pav), linimon (mentor)
Original commit
Monday, 5 Nov 2007
21:12 miwi search for other commits by this committer
- gftp -- multiple vulnerabilities

Reviewed by:    simom
Approved by:    portmgr (blanket) (ports-security blanket)
Original commit
11:46 miwi search for other commits by this committer
- Update dirproxy -- remote denial of service
         * Add net/dirproxy with the same affect
         * Update net/dirproxy-devel as safe

Reviewed by:    simon
Approved by:    portmgr (blanket) (ports-security blanket)
Original commit
Sunday, 4 Nov 2007
13:43 miwi search for other commits by this committer
- dirproxy -- remote denial of service

Reviewed by:    remko
Approved by:    portmgr (blanket) (ports-security blanket)
Original commit
Thursday, 1 Nov 2007
15:16 miwi search for other commits by this committer
- Fix discovery date on my previous commit

Approved by:    portmgr (ports-security blanket)
Original commit
12:46 miwi search for other commits by this committer
- document wordpress -- cross-site scripting

Reviewed by:    simon
Approved by:    portmgr (ports-security blanket)
Original commit
00:58 delphij search for other commits by this committer
Extend coverage to OpenLDAP 2.4.x series which is affected according
to CVS history.

Approved by:    portmgr (ports-security blanket)
Original commit
Wednesday, 31 Oct 2007
21:48 delphij search for other commits by this committer
Document openldap multiple vulnerabilities.

Approved by:    portmgr (ports-security blanket)
Original commit
17:21 simon search for other commits by this committer
Bump modified date for entry updated in last commit.

Approved by:    portmgr (secteam blanket)
Original commit
16:38 girgen search for other commits by this committer
Update vuxml to reflect that mod_jk and mod_jk-ap2 have
different portepochs.

Approved by:    portmgr (pav)
Original commit
12:44 miwi search for other commits by this committer
- Update mozilla -- code execution via Quicktime media-link files

PR:             117704
Submitted by:   John Hein <jhein@timing.com>
Reviewed by:    simon
Approved by:    portmgr (blanket) secteam (blanket via simon)
Original commit
Sunday, 28 Oct 2007
22:22 delphij search for other commits by this committer
Document django DoS issue.
Original commit
Friday, 26 Oct 2007
20:41 miwi search for other commits by this committer
- Fix day entry for 498a8731-7cfc-11dc-96e6-0012f06707f0

Reviewed by:    simon
Original commit
Thursday, 25 Oct 2007
18:34 miwi search for other commits by this committer
- Document opera -- multiple vulnerabilities

Reviewed by:    remko
Original commit
08:47 miwi search for other commits by this committer
- Document drupal --- multiple vulnerabilities

Reviewed by:    simon
Original commit
Tuesday, 23 Oct 2007
11:12 miwi search for other commits by this committer
- Document ldapscripts -- Command Line User Credentials Disclosure

PR:             117152
Submitted by:   Ganael Laplanche <ganael.laplanche at martymac.com>
(maintainer/author)
                rafan@
Reviewed by:    simon@
Original commit
Monday, 22 Oct 2007
18:51 delphij search for other commits by this committer
Modify firefox entry to cover linux-* variants.
Original commit
01:37 delphij search for other commits by this committer
Document firefox JavaScript Entrapment vulnerabilities.
Original commit
Saturday, 20 Oct 2007
20:48 miwi search for other commits by this committer
- Fix year entry in 498a8731-7cfc-11dc-96e6-0012f06707f0

Submitted by:   freshports
Thanks to:      Dan Langille
Original commit
Friday, 19 Oct 2007
14:23 mnag search for other commits by this committer
- Add new line between entries.
Original commit
Wednesday, 17 Oct 2007
22:15 stas search for other commits by this committer
- Add entry about recent phpMyAdmin XSS server_status.php vulnerability
- Fix URL in my previous entry while I'm here.
Original commit
Tuesday, 16 Oct 2007
18:29 stas search for other commits by this committer
- Fix package name in 51b51d4a-7c0f-11dc-9e47-0011d861d5e2 and
  229577a8-0936-11db-bf72-00046151137e entries (phpmyadmin->phpMyAdmin).
Original commit
18:13 stas search for other commits by this committer
- Add entry about phpMyAdmin XSS vulnerability.
Original commit
Saturday, 13 Oct 2007
09:45 miwi search for other commits by this committer
nagios-plugins -- Long Location Header Buffer Overflow Vulnerability

Reviewed by:    simon
Original commit
Thursday, 11 Oct 2007
17:28 miwi search for other commits by this committer
Document png -- multiple vulnerabilities

Reviewed by:    simon
Original commit
Wednesday, 10 Oct 2007
12:47 remko search for other commits by this committer
Document ImageMagick - Multiple vulnerabilities

Submitted by:           Nick Barkas
Original commit
12:35 remko search for other commits by this committer
Correct mediawiki package names.

Spotted by:     Nick Barkas
Original commit
Tuesday, 9 Oct 2007
07:18 miwi search for other commits by this committer
- Dokument jdk/jre -- Applet Caching May Allow Network Access Restrictions to be
Circumvented

Reviewed by:    remko
Original commit
Monday, 8 Oct 2007
12:05 flz search for other commits by this committer
Document xfs -- multiple vulnerabilities.
Original commit
Friday, 5 Oct 2007
09:35 miwi search for other commits by this committer
- Document tcl/tk -- buffer overflow in ReadImage function

PR:             116881
Submitted by:   Nick Barkas <snb@threerings.net>
Reviewed by:    simon
Original commit
Thursday, 4 Oct 2007
22:56 delphij search for other commits by this committer
Document firebird multiple remote buffer overflow vulnerabilities
Original commit
Tuesday, 2 Oct 2007
18:27 remko search for other commits by this committer
Update the bugzilla and mediawiki entries to properly match their corrected
versions.

Prodded by:     Nick Barkas (and a few others)
Original commit
02:04 delphij search for other commits by this committer
Update to reflect the fixed version of id3lib.
Original commit
Monday, 1 Oct 2007
21:04 delphij search for other commits by this committer
Document id3lib insecure temporary file creation vulnerability
Original commit
Sunday, 23 Sep 2007
09:09 miwi search for other commits by this committer
- modify mediawiki entry (add missing mediawiki18)

Reviewed by:    remko
Original commit
01:37 delphij search for other commits by this committer
Some PHP 5.x vulnerabilities is also found in PHP 4.x series,
unfortunately it seems that there is no newer PHP release to
fix these issue for 4.x series, so mark it as so.

While I'm there add a new CVE that was not mentioned in
previous revision of entry.
Original commit
Friday, 21 Sep 2007
13:14 remko search for other commits by this committer
Document mediawiki -- cross site scripting vulnerability, our port versions
had not been updated yet, 1.8.x is not vulnerable by default unless you are
using the $wgEnableAPI = true; statement, in that case please set it to
$wgEnableAPI = false; (where possible ofcourse, else upgrade to 1.8.5).
Original commit
13:02 remko search for other commits by this committer
Document wordpress -- remote sql injection vulnerability, our versions are
already up to date for this vulnerability.
Original commit
12:41 remko search for other commits by this committer
samba -- nss_info plugin privilege escalation vulnerability, the FreeBSD
port had already been fixed for this.
Original commit
06:49 remko search for other commits by this committer
Document bugzilla -- multiple vulnerabilities

PR:             ports/116060
Submitted by:   Nick Barkas <snb at threerings dot net>, minor nits from me
Original commit
06:35 delphij search for other commits by this committer
Document clamav CVE-2007-4510 issue (Remote DoS).
Original commit
Thursday, 20 Sep 2007
12:20 remko search for other commits by this committer
Document coppermine -- multiple vulnerabilities, the FreeBSD
port is already up to date.
Original commit
12:12 remko search for other commits by this committer
Document openoffice -- arbitrary command execution vulnerability,
all current versions marked vulnerable, everything as of 2.3 is
believed to be fixed, but we do not have that yet ( I am also not
sure whether the -devel version has the correct fix or not ) so
lets be on the safe side till we know what version will be fixed
in our repro.
Original commit
12:04 remko search for other commits by this committer
Document bugzilla -- "createmailregexp" security bypass vulnerability,
marking all versions as vulnerable till we know what version is the
one fixed in our CVS repository.
Original commit
Wednesday, 19 Sep 2007
19:24 simon search for other commits by this committer
Spell Ulf Harnhammar (ASCII version of name) using UTF-8 instead of HTML
entities which can't be assumed is available to a paser by default.

This fixes a warning from packaudit.
Original commit
17:06 remko search for other commits by this committer
Document kdm -- passwordless login vulnerability
Document konquerer -- address bar spoofing

Inspired by:    lofi's cvs commits
Original commit
16:56 remko search for other commits by this committer
Document flyspray -- authentication bypass

Submitted by:   Nick Hilliard <nick at foobar dot org>
Original commit
16:50 remko search for other commits by this committer
Document mozilla -- code execution via Quicktime media-link files,
The Mozilla advisory talks somewhat about Windows for this matter,
but better be safe then sorry (An updated firefox is available already).
Original commit
Thursday, 13 Sep 2007
05:50 delphij search for other commits by this committer
Update the PHP vulnerability entry:

 - Use php5 to cover php 5.x as the port did.
 - Add more information about the vulnerability.

Submitted by:   Nick Barkas <snb threerings net>
PR:             ports/116182
Original commit
Tuesday, 11 Sep 2007
19:40 remko search for other commits by this committer
Correct a style nit and bump modification date.
Bump modification date for "xpdf -- stack based buffer overflow"
which was forgotten by Jeremy (mezz) :-)
Original commit
06:20 delphij search for other commits by this committer
Document Apache 2.0.x, 2.2.x series' vulnerabilities as well
as security related improvements in php 5.2.4.
Original commit
Monday, 10 Sep 2007
21:59 mezz search for other commits by this committer
There is no code of CVE-2007-3387 vulnerability in evince, therefore remove
it from the database. It only merely depends on poppler and poppler has been
patched (marked as safe in database).
Original commit
13:37 mnag search for other commits by this committer
- lighttpd -- FastCGI header overrun in mod_fastcgi
Original commit
Wednesday, 5 Sep 2007
11:26 remko search for other commits by this committer
Fix mod_jk's version since PORTEPOCH came into play.

PR:             116115
Reported by:    Klavs Klavsen <klavs at EnableIT dot dk>
Original commit
08:50 gabor search for other commits by this committer
rkhunter -- insecure temporary file creation

Reviewed by:    remko
Original commit
08:47 gabor search for other commits by this committer
lsh -- multiple vulnerabilities

Reviewed by:    remko
Original commit
Sunday, 2 Sep 2007
12:09 simon search for other commits by this committer
Document fetchmail -- denial of service on reject of local
warning message.

Submitted by:   Matthias Andree <matthias.andree@gmx.de>
PR:             ports/??? (Not received by GNATS yet)
Original commit
Saturday, 1 Sep 2007
16:04 naddy search for other commits by this committer
Document gtar directory traversal vulnerability.

PR:             115914
Submitted by:   Nick Barkas <snb@threerings.net>
Original commit
Tuesday, 28 Aug 2007
21:03 miwi search for other commits by this committer
- Marked sylpheed2 as safe.

Reviewed by:    remko
Original commit
Monday, 27 Aug 2007
19:52 miwi search for other commits by this committer
- Fix a typo.
Original commit
19:44 miwi search for other commits by this committer
- Document Sylpheed / Sylpheed-Claws POP3 Format String Vulnerability

Reviewed by:    simon
Original commit
Saturday, 25 Aug 2007
19:36 simon search for other commits by this committer
From latest Opera entry:
- Remove redundant information.
- Bump modified date for recent changes to the entry.
Original commit
Friday, 24 Aug 2007
15:20 itetcu search for other commits by this committer
linux-opera and (for the moment defunct) opera-devel are also affected by
df4a7d21-4b17-11dc-9fc2-001372ae3ab9 - Vulnerability in javascript handling so
addd them to the entry.

Submitted by:   sat@
Original commit
Wednesday, 22 Aug 2007
16:31 delphij search for other commits by this committer
Update vuln.xml for rsync 2.6.9_1 which fixed CVE-2007-4091
Original commit
Tuesday, 21 Aug 2007
17:20 delphij search for other commits by this committer
Document rsync off-by-one stack overflow vulnerability.
Original commit
Thursday, 16 Aug 2007
11:53 miwi search for other commits by this committer
- Update the wordpress -- unmoderated comments disclosure entry. Is safe with
the 2.2.2 Release.

Approved by:    simon
Original commit
Wednesday, 15 Aug 2007
12:15 itetcu search for other commits by this committer
Add info about www/opera's JavaScript vulnerability

PR:             ports/115543
Submitted by:   Arjan van Leeuwen (maintainer)
Reviewed by:    simon@
Original commit
Friday, 10 Aug 2007
07:31 remko search for other commits by this committer
Fix the flac entry by specificing the correct fixed version.
Bump modification date to reflect the above change.

Submitted by:   Stefan Ehmann
Original commit
Thursday, 2 Aug 2007
19:52 miwi search for other commits by this committer
- Document fsplib -- multiple vulnerabilities

Reviewed by:    remko
Original commit
18:50 miwi search for other commits by this committer
Document joomla -- multiple vulnerabilities

Approved by:    simon/remko
Original commit
11:09 remko search for other commits by this committer
Use the superseded attribute in the cancelled tcpdump entry.

Requested by:   simon
Original commit
07:22 remko search for other commits by this committer
Document FreeBSD -- Buffer overflow in tcpdump(1).

See: FreeBSD-SA-07:06.tcpdump

This commit also takes over the older tcpdump entry that was specific
to ports, I merged that into this entry and I retired the old one.
Original commit
06:18 remko search for other commits by this committer
Bump modification date for: SA-07:04.file
Which I just touched.
Original commit
06:17 remko search for other commits by this committer
Correct the fixed version for the jail advisory which was revised yesterday.

Also correct the <freebsdsa>FreeBSD-SA* tags which should not have FreeBSD
in between.
Original commit
06:15 remko search for other commits by this committer
Document FreeBSD -- Predictable query ids in named(8)

See: FreeBSD-SA-07:07.bind
Original commit
Wednesday, 1 Aug 2007
17:51 miwi search for other commits by this committer
- Marked phpSysInfo as safe

Reviewed by:    remko
Original commit
00:47 shaun search for other commits by this committer
Update phpSysInfo entry: the current version (2.5.3) is affected.
Original commit
Tuesday, 31 Jul 2007
22:21 miwi search for other commits by this committer
Update mozilla entry
- Marked seamonkey as safe

Submitted by:   John E. Hein <jhein@timing.com>
Reviewed by:    simon
Original commit
14:43 miwi search for other commits by this committer
Update the xpdf entry
- Marked poppler as save
Original commit
13:33 miwi search for other commits by this committer
Update xpdf entry
- Marked cups-base as safe
- Add poppler as affected port

Reviewed by:    simon
Original commit
11:31 miwi search for other commits by this committer
- Fix tcpdump entry
Original commit
11:30 miwi search for other commits by this committer
Document xpdf -- stack based buffer overflow

Reviewed by:    simon/remko
Original commit
09:49 miwi search for other commits by this committer
- Fix a typo

Submitted by:   shaun
Original commit
07:50 miwi search for other commits by this committer
- Document tcpdump -- remote integer underflow vulnerability

Reviewed by:    remko
Original commit
Sunday, 29 Jul 2007
18:28 miwi search for other commits by this committer
- Document mutt -- buffer overflow vulnerability

Reviewed by:    remko
Original commit
11:29 miwi search for other commits by this committer
- Document p5-Net-DNS -- multiple Vulnerabilities

Reviewed by:    remko
Original commit
Saturday, 28 Jul 2007
21:52 miwi search for other commits by this committer
- Document phpsysinfo -- url Cross-Site Scripting
Original commit
15:28 miwi search for other commits by this committer
- Document drupal -- Cross site request forgeries
- Document drupal -- Multiple cross-site scripting vulnerabilities

Submitted by:   nick@foobar.org
Reviewed by:    simon
Original commit
Friday, 27 Jul 2007
18:04 miwi search for other commits by this committer
- Document vim -- Command Format String Vulnerability

Approved by:    simon
Original commit
Thursday, 26 Jul 2007
22:06 miwi search for other commits by this committer
- Document libvorbis - Multiple memory corruption flaws

Submitted by:   lx@
Reviewed by:    simon
Original commit
Tuesday, 24 Jul 2007
14:31 delphij search for other commits by this committer
Document XSS vulnerabilities in several tomcat versions;
update affected tomcat versions for CVE-2005-2090.
Original commit
14:17 delphij search for other commits by this committer
The previous vuxml entry applies to jakarta-tomcat 4.0.x as well, so mark
it as affected as well.  Since there is no newer release I have used 4.1.0
as the "fixed" version.
Original commit
13:54 delphij search for other commits by this committer
Document multiple vulnerabilities found in www/tomcat41
Original commit
08:00 delphij search for other commits by this committer
Document dokuwiki spellchecker XSS vulnerabilities
Original commit

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  44 | 45 | 46 | 47 | 48 | 49 | 50 | 51 | 52 | 53 | 54  »  [Last Page]