notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
This referral link gives you 10% off a Fastmail.com account and gives me a discount on my Fastmail account.

Get notified when packages are built

A new feature has been added. FreshPorts already tracks package built by the FreeBSD project. This information is displayed on each port page. You can now get an email when FreshPorts notices a new package is available for something on one of your watch lists. However, you must opt into that. Click on Report Subscriptions on the right, and New Package Notification box, and click on Update.

Finally, under Watch Lists, click on ABI Package Subscriptions to select your ABI (e.g. FreeBSD:14:amd64) & package set (latest/quarterly) combination for a given watch list. This is what FreshPorts will look for.

non port: security/vuxml/vuln.xml

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63  »  [Last Page]

Tuesday, 23 Nov 2004
13:52 simon search for other commits by this committer
Document that the twiki vulnerability is fixed in twiki-20040902.
Original commit
06:29 ume search for other commits by this committer
add Cyrus IMAP Server multiple remote vulnerabilities.

Obtained from:  http://security.e-matters.de/advisories/152004.html
Original commit
Saturday, 20 Nov 2004
22:21 simon search for other commits by this committer
Add CVE reference for the SA-04:16.fetch entry.
Original commit
00:39 josef search for other commits by this committer
Document vulnerability in phpmyadmin.
Original commit
Thursday, 18 Nov 2004
19:06 josef search for other commits by this committer
Add localized versions of gd port to the VuXML entry.
Original commit
15:47 simon search for other commits by this committer
Document SA-04:16.fetch.
Original commit
Wednesday, 17 Nov 2004
19:05 josef search for other commits by this committer
Document the buffer overrun vulnerability in samba3
CAN-2004-882
Original commit
17:11 josef search for other commits by this committer
Correct range for xpdf vulnerability, as cups-base got a fixing
update.
Original commit
Tuesday, 16 Nov 2004
23:16 josef search for other commits by this committer
The last commit to japanese/samba also fixed the security issue
in samba (CAN-2004-0815)

As discussed with:      NAKAJI Hiroyuki <nakaji@jp.freebsd.org> (maintainer)
Original commit
22:53 simon search for other commits by this committer
Add CVE name to twiki entry.

Noticed by:     josef
Original commit
20:02 josef search for other commits by this committer
Add teTeX-base to affected packages in xpdf's vuxml entry.
Original commit
Monday, 15 Nov 2004
10:18 simon search for other commits by this committer
Document arbitrary shell command execution in twiki.
Original commit
Sunday, 14 Nov 2004
23:05 simon search for other commits by this committer
Document a format string vulnerability in proxytunnel.
Original commit
Saturday, 13 Nov 2004
09:05 simon search for other commits by this committer
Fix entry date for the ruby entry from the last commit.
Original commit
08:54 simon search for other commits by this committer
- Document at DoS in the Ruby CGI module.
- Document a privilege escalation in sudo.
Original commit
Friday, 12 Nov 2004
15:23 nectar search for other commits by this committer
Add CVE name for gnats issue.
Original commit
15:01 nectar search for other commits by this committer
Note (likely) remotely exploitable vulnerability in samba 3.

Submitted by:   Shane Kinney <mod6@freebsdhackers.net>
Original commit
11:15 josef search for other commits by this committer
Document vulnerability in GNATS.
Original commit
Thursday, 11 Nov 2004
23:53 simon search for other commits by this committer
Document a XSS in squirrelmail.
Original commit
23:01 josef search for other commits by this committer
Fix entry date.
Original commit
22:46 josef search for other commits by this committer
Document BNC vulnerability.
Original commit
17:29 nectar search for other commits by this committer
Note old hafiye bug.

Submitted by:   Shane Kinney <mod6@freebsdhackers.net>
Original commit
15:46 naddy search for other commits by this committer
Fix a format string vulnerability in ez-ipupdate.

Approved by:    se@
Obtained from:  Ulf Harnhammar <Ulf.Harnhammar.9485@student.uu.se>
Original commit
14:17 simon search for other commits by this committer
Document a buffer overflow in ImageMagick's EXIF parser.
Original commit
13:34 simon search for other commits by this committer
Correct recent Apache 2 entry to not match Apache 1.X.

Noticed by:     Dan Langille <dan@langille.org>
Original commit
Wednesday, 10 Nov 2004
22:48 josef search for other commits by this committer
Document vulnerability in Apache 2 (CAN-2004-0942).
Original commit
20:25 marcus search for other commits by this committer
Update the libxml vulnerability to indicate the fixed version.
Original commit
Tuesday, 9 Nov 2004
23:30 simon search for other commits by this committer
Document a format string vulnerability in socat.
Original commit
22:07 simon search for other commits by this committer
Document remote buffers overflow in libxml and libxml2.
Original commit
17:00 nectar search for other commits by this committer
The bugs discovered by Chris Evans have been fixed
in linux-gdk-pixbuf.

Reported by:    thierry
Original commit
Monday, 8 Nov 2004
10:26 josef search for other commits by this committer
Fix pkgnames for mod_include vulnerability.
Thanks to Dan Langille for helping me to track these down.
Original commit
00:07 simon search for other commits by this committer
Document a virus detection evasion in p5-Archive-Zip.
Original commit
Saturday, 6 Nov 2004
12:31 josef search for other commits by this committer
Document mod_include vulnerability in apache and related ports.
Original commit
00:38 simon search for other commits by this committer
Document an insecure temporary file creation in postgresql-contrib.
Original commit
Friday, 5 Nov 2004
21:57 simon search for other commits by this committer
Bump modified date in the entry for the last commit.
Original commit
21:54 simon search for other commits by this committer
Update latest mpg123 entry to note that the port is fixed in the most
recent port version.
Original commit
14:48 simon search for other commits by this committer
There was a gd 1.X port with portepoch 2 for a while, so let the gd
entry also match that.
Original commit
13:59 simon search for other commits by this committer
Document an integer overflow in the GD Graphics Library.
Original commit
Thursday, 4 Nov 2004
08:56 simon search for other commits by this committer
Correct entry date for the putty entry.

OK'ed by:       josef
Original commit
00:05 josef search for other commits by this committer
Document vulnerability in putty

Reviewed by:    simon
Original commit
Wednesday, 3 Nov 2004
22:49 simon search for other commits by this committer
Add an entry for a wzdftpd remote DoS.
Original commit
22:36 simon search for other commits by this committer
Updates to the bogofilter entry:

- Improve information about which versions are vulnerable. [1]
- Add a few more references.

Submitted by:   Matthias Andree <matthias.andree@gmx.de> [1]
Original commit
Monday, 1 Nov 2004
21:24 mezz search for other commits by this committer
Update linux-openmotif to 2.2.4 to fix the security.

http://vuxml.freebsd.org/ef253f8b-0727-11d9-b45d-000c41e2cdad.html
Original commit
Wednesday, 27 Oct 2004
21:11 josef search for other commits by this committer
Document rssh format string vulnerability.

Approved by:    nectar
Original commit
12:25 nectar search for other commits by this committer
Create a VuXML entry for Horde XSS help window vulnerability to replace
the portaudit-db entry.
Original commit
Tuesday, 26 Oct 2004
11:12 nectar search for other commits by this committer
Document a denial-of-service issue in bogofilter.
This entry is slightly modified from one that was
Submitted by:   Matthias Andree <matthias.andree@gmx.de>
Original commit
05:41 nork search for other commits by this committer
Fix integer overflow vulnerabilities.

Patch made by:  Chris Evans, Dirk Muller, Sebastian Krahmer,
                Derek Noonburg and Marcus Meissner
Submitted by:   nectar
Original commit
Monday, 25 Oct 2004
20:22 nectar search for other commits by this committer
Document xpdf 2 and xpdf 3 vulnerabilities.
Original commit
19:27 nectar search for other commits by this committer
Document several security issues in gaim, fixed in various versions from
0.82 through 1.0.2.  While I'm here, notice that there have been ru-,
ko-, and ja- flavors of gaim, as well as a fairly short-lived range of
version numbers based on dates (snapshots).
Original commit
17:21 nectar search for other commits by this committer
Note that the Red Hat based linux_base ports contain
vulnerable libXpm.so files.

Noticed by:     maho
Original commit
Sunday, 24 Oct 2004
19:39 josef search for other commits by this committer
Document SSL_Cypherbypass vulnerability in mod_ssl
and buffer overflow vulnerability in gaim.
Original commit
Saturday, 23 Oct 2004
16:08 simon search for other commits by this committer
- Document more buffer overflows in mpg123.
- Fix package name in two older mpg123 entries.

Approved by:    nectar
Original commit
Friday, 22 Oct 2004
12:21 nectar search for other commits by this committer
I suck.    (Correct a typo that would have been readily detected if
            I would have run `make validate' before committing.)
Original commit
12:13 nectar search for other commits by this committer
Add CVE name for cabextract issue.
Original commit
Thursday, 21 Oct 2004
22:23 simon search for other commits by this committer
Fix a copy/paste typo in last commit.
Original commit
22:17 simon search for other commits by this committer
Document DoS in Apache 2 SSL handling.

Approved by:    nectar
Original commit
20:04 nectar search for other commits by this committer
Note that xpm has been fixed.
Also, it appears that Motif itself is affected, so add related packages.
Original commit
12:34 nectar search for other commits by this committer
Update entry regarding INN 2.4.x buffer overflow:
 - The email archive referenced is no longer available.  Use
   marc.theaimsgroup.com archive instead.
 - Note that only 2.4.x versions are affected (earlier ones
   are not).

Reported by:    leeym
Original commit
Wednesday, 20 Oct 2004
21:21 simon search for other commits by this committer
Document remote command execution vulnerability in phpMyAdmin.

Approved by:    nectar
Original commit
18:38 simon search for other commits by this committer
Document insecure directory handling in cabextract.

Approved by:    nectar
Original commit
Tuesday, 19 Oct 2004
22:08 simon search for other commits by this committer
Set correct entry date for the a2ps issue.

Noticed by:     nectar
Pointy hat to:  simon
Original commit
21:41 simon search for other commits by this committer
Document insecure command line argument handling in a2ps.

Approved by:    nectar
Original commit
16:40 nectar search for other commits by this committer
Document a vulnerability in ifmail.  (There does not exist
an appropriate public reference yet--- this entry should be
updated when the port is updated.)

Reported by:    Niels Heinen <niels.heinen@ubizen.com>
Original commit
15:41 nectar search for other commits by this committer
Document a vulnerability in imwheel.
Original commit
14:11 nectar search for other commits by this committer
Add CVE names for FreeRADIUS vulnerabilities.
Original commit
Monday, 18 Oct 2004
20:21 josef search for other commits by this committer
Document NTLM authentication vulnerability in squid

Approved by:    nectar
Original commit
17:56 simon search for other commits by this committer
Document a SQL command injection in Cacti.

The status of the PHP configuration option magic_quotes_gpc was
confirmed by:   ale

Approved by:    nectar
Original commit
Sunday, 17 Oct 2004
16:38 simon search for other commits by this committer
Document a format string vulnerability in the apache13 mod_ssl proxy
support.

Approved by:    nectar
Original commit
Saturday, 16 Oct 2004
20:31 simon search for other commits by this committer
- Change a few uses of <url> into <mlist>.

OK'ed by:       nectar

Additional comment to the Tor entry from v. 1.302, it was:

Submitted by:   rik <freebsd-security@rikrose.net> (original version)
Original commit
Friday, 15 Oct 2004
21:21 simon search for other commits by this committer
- Document remote DoS and loss of anonymity in Tor.
- Update a Samba entry with new information about vulnerable versions.

Approved by:    nectar
Original commit
Thursday, 14 Oct 2004
17:52 nectar search for other commits by this committer
lesstif has been upgraded to a version that is not affected by the
libXpm vulnerability.
Original commit
17:06 simon search for other commits by this committer
Recommit my changes from 1.298 which was accidently removed in 1.299.

Pointy hat to:  josef (who also noticed the problem)
Original commit
16:55 josef search for other commits by this committer
Document two seperate security vulnerabilities in
icecast1 and icecast2.

Approved by:    nectar
Original commit
16:46 simon search for other commits by this committer
Change the Xerces-C++ entry to match the xerces-c2 port.

Noticed by:     nectar
Original commit
Wednesday, 13 Oct 2004
22:00 josef search for other commits by this committer
Document vulnerability in freeradius.

Approved by:    nectar
Original commit
21:50 simon search for other commits by this committer
- Document DoS in Xerces-C++.
- Fix typo in a mozilla entry.

Approved by:    nectar
Original commit
21:12 nectar search for other commits by this committer
It turns out that lesstif has libXpm sneakily embedded.  There are at
least three files with this comment at the top:

  * This file contains most of the source files of Xpm, concatenated and with
  * the public names changed (to have an _LtXpm prefix).
Original commit
21:01 simon search for other commits by this committer
Document XSS in wordpress.

Approved by:    nectar
Original commit
20:39 nectar search for other commits by this committer
Document integer overflows in libtiff.
Original commit
17:18 simon search for other commits by this committer
- Document a CUPS local information disclosure.
- Note the impact of the sharutils buffer overflows.

Approved by:    nectar
Original commit
16:55 josef search for other commits by this committer
Document a vulnerability in Zinf (freeamp).

Approved by:    nectar
Original commit
16:06 nectar search for other commits by this committer
Document libtiff RLE decoder issues.
Original commit
10:27 simon search for other commits by this committer
The sharutils buffer overflows has been fixed in sharutils 4.2.1_2.
Original commit
Tuesday, 12 Oct 2004
23:46 simon search for other commits by this committer
Document a vulnerability in sharutils.

Approved by:    nectar
Original commit
21:58 josef search for other commits by this committer
Document 2 DoS attacks possible against
older versions of mail-notifier.

Based on the security advisories
mentioned in the reference links.

Approved by:    nectar
Original commit
15:39 nectar search for other commits by this committer
ale@ reports that the only ports affected are php[45], php[45]-cgi,
and mod_php[45].
Original commit
15:09 nectar search for other commits by this committer
Note squid SNMP DoS.  Based on an entry that was
Submitted by:   Thomas-Martin Seck <tmseck@netcologne.de>
Original commit
02:08 nectar search for other commits by this committer
The documented xv vulnerabilities were fixed by dinoex@

Approved by:    portmgr
Original commit
01:07 nectar search for other commits by this committer
Note that the image decoding vulnerabilities in gdk-pixbuf have been
fixed.

Reported by:    marcus
Approved by:    portmgr
Original commit
00:58 nectar search for other commits by this committer
Document older cyrus-sasl bug affecting DIGEST-MD5.

Submitted by:   simon
Approved by:    portmgr
Original commit
00:57 nectar search for other commits by this committer
Update the description of and list of packages affected by the PHP file
upload processing bug.

Submitted by:   Jon Passki <cykyc@yahoo.com>
Approved by:    portmgr
Original commit
Friday, 8 Oct 2004
16:50 nectar search for other commits by this committer
Document unsafe use of environmental variable SASL_PATH in cyrus-sasl.

Approved by:    portmgr
Original commit
Tuesday, 5 Oct 2004
19:28 trhodes search for other commits by this committer
Add some more apache ports.
Fix two errors found by nectar.

Approved by:    portmgr
Original commit
17:41 trhodes search for other commits by this committer
Add imp3 issue, add apache13-ssl issue, correct a tag.

Approved by:    portmgr
Original commit
14:54 nectar search for other commits by this committer
Note that older packages of bmon were dangerously installed set-user-ID.

Approved by:    portmgr
Original commit
14:33 nectar search for other commits by this committer
Document GnuTLS denial-of-service (already mentioned in portaudit's
database).

Approved by:    portmgr
Original commit
14:06 nectar search for other commits by this committer
Record another PHP vulnerability.

Approved by:    portmgr
Original commit
13:52 nectar search for other commits by this committer
Record another PHP security issue.

Approved by:    portmgr
Original commit
12:52 nectar search for other commits by this committer
Note that xv should not be used.

Approved by:    portmgr
Original commit
Monday, 4 Oct 2004
19:59 nectar search for other commits by this committer
Note a symlink vulnerability in getmail.

Submitted by:   Shane Kinney <mod6@freebsdhackers.net>
Approved by:    portmgr
Original commit

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  53 | 54 | 55 | 56 | 57 | 58 | 59 | 60 | 61 | 62 | 63  »  [Last Page]