notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
This referral link gives you 10% off a Fastmail.com account and gives me a discount on my Fastmail account.

Get notified when packages are built

A new feature has been added. FreshPorts already tracks package built by the FreeBSD project. This information is displayed on each port page. You can now get an email when FreshPorts notices a new package is available for something on one of your watch lists. However, you must opt into that. Click on Report Subscriptions on the right, and New Package Notification box, and click on Update.

Finally, under Watch Lists, click on ABI Package Subscriptions to select your ABI (e.g. FreeBSD:14:amd64) & package set (latest/quarterly) combination for a given watch list. This is what FreshPorts will look for.

non port: security/vuxml/vuln.xml

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14  »  [Last Page]

Tuesday, 2 Apr 2019
07:58 brnrd search for other commits by this committer
security/vuxml: Document Apache httpd vulnerabilities
Original commitRevision:497553 
Monday, 1 Apr 2019
19:29 danilo search for other commits by this committer
- Document sysutils/kubectl CVE-2019-1002101
Original commitRevision:497507 
Sunday, 31 Mar 2019
13:50 dbaio search for other commits by this committer
security/vuxml: Document irc/znc issue

Security:	CVE-2019-9917
Original commitRevision:497423 
Friday, 29 Mar 2019
16:36 sunpoet search for other commits by this committer
Document py-notebook vulnerability
Original commitRevision:497167 
14:17 sunpoet search for other commits by this committer
Update openjpeg status
Original commitRevision:497140 
Thursday, 28 Mar 2019
12:21 ler search for other commits by this committer
vuxml: Document mail/dovecot buffer overflow.
Original commitRevision:497014 
08:26 joneum search for other commits by this committer
Add modified line for drupal after r496987

Sponsored by:	Netzkommune GmbH
Original commitRevision:497005 
Wednesday, 27 Mar 2019
21:51 acm search for other commits by this committer
- Update 94d63fd7-508b-11e9-9ba0-4c72b94353b5 entry
Original commitRevision:496987 
19:23 sunpoet search for other commits by this committer
Update Python vulnerability (d74371d2-4fee-11e9-a5cd-1df8a848de3d)
Original commitRevision:496976 
17:44 joneum search for other commits by this committer
Add entry for www/drupal7

Sponsored by:	Netzkommune GmbH
Original commitRevision:496953 
Tuesday, 26 Mar 2019
18:12 sunpoet search for other commits by this committer
Document Python vulnerability
Original commitRevision:496919 
Friday, 22 Mar 2019
04:08 zeising search for other commits by this committer
Update the libXdmcp entry to make it clearer.
Original commitRevision:496547 
Thursday, 21 Mar 2019
09:36 joneum search for other commits by this committer
Add entry for wordpress

Sponsored by:	Netzkommune GmbH
Original commitRevision:496435 
08:15 mfechner search for other commits by this committer
Documented gitlab vulnerability.
Original commitRevision:496430 
02:03 zeising search for other commits by this committer
Add entry for x11/libXdmcp vulnerabilty.

Add entry for x11/libXdmcp vulnerabilty, insufficient entripy generating
session keys.  It is unknown if this actually affects FreeBSD.

Security:	CVE-2017-2625
Original commitRevision:496407 
Wednesday, 20 Mar 2019
14:04 mfechner search for other commits by this committer
Documented security vulnerability for gitlab < 11.8.2.
Original commitRevision:496343 
11:30 joneum search for other commits by this committer
Add entry for www/gitea

PR:		236563
Original commitRevision:496333 
Tuesday, 19 Mar 2019
20:22 jbeich search for other commits by this committer
security/vuxml: mark firefox < 66 as vulnerable
Original commitRevision:496292 
14:51 swills search for other commits by this committer
Document PowerDNS issue

PR:		236634
Reported by:	Dani <i.dani@outlook.com>
Original commitRevision:496262 
Monday, 18 Mar 2019
18:25 sunpoet search for other commits by this committer
Document Rails vulnerability
Original commitRevision:496197 
Sunday, 17 Mar 2019
14:16 mandree search for other commits by this committer
Record PuTTY security vulnerabilities in versions before 0.71.
Original commitRevision:496062 
Saturday, 16 Mar 2019
23:23 sunpoet search for other commits by this committer
Document py-notebook vulnerability
Original commitRevision:495996 
Friday, 15 Mar 2019
21:42 sunpoet search for other commits by this committer
Document ruby-gems vulnerability
Original commitRevision:495829 
Tuesday, 12 Mar 2019
06:14 riggs search for other commits by this committer
Document CVE fixes in libsndfile-1.0.28_2

PR:		227669
Reported by:	p5B2E9A8F@t-online.de
Original commitRevision:495442 
Friday, 8 Mar 2019
02:26 cy search for other commits by this committer
Fill in the actual URL for March 2019 ntp-4.2.8p13 NTP Release and
Security Vulnerability Announcement
Original commitRevision:495009 
Thursday, 7 Mar 2019
19:33 brnrd search for other commits by this committer
security/vuxml: Document OpenSSL 1.1.1 vulnerability
Original commitRevision:494994 
13:32 cy search for other commits by this committer
Document crafted ull dereference ntp attack.

Security:	CVE-2019-8936
Obtained from:	nwtime.org
Original commitRevision:494940 
Wednesday, 6 Mar 2019
19:56 kai search for other commits by this committer
security/vuxml: Document shells/rssh < 2.3.4_2 vulnerabilities

PR:		235121
Approved by:	tcberner (mentor)
Differential Revision:	https://reviews.freebsd.org/D19473
Original commitRevision:494835 
07:31 matthew search for other commits by this committer
Document a jQuery related XSS security fix in rt4.4.4 and rt4.2.16

Note: the release notes also mention 3 other security issues in perl
modules depended on by these packages.  Of those, vulnerabilities in
the Email::Address and Email::Address::List perl modules have already
been addressed in their respective ports, while the third: HTML::Gumbo
is not currently in the ports at all.
Original commitRevision:494780 
Tuesday, 5 Mar 2019
15:00 0mp search for other commits by this committer
Document a slixmpp < 1.4.1 vulnerability

Reviewed by:	krion, mat
Approved by:	krion (mentor), mat (mentor)
MFH:		2019Q1
Original commitRevision:494705 
10:23 mfechner search for other commits by this committer
Doucumented several www/gitlab-ce security vulnerabilities.
Original commitRevision:494691 
06:20 tobik search for other commits by this committer
Document www/py-gunicorn vulnerability
Original commitRevision:494678 
Monday, 4 Mar 2019
10:54 joneum search for other commits by this committer
Update mybb entry

Sponsored by:	Netzkommune GmbH
Original commitRevision:494582 
Sunday, 3 Mar 2019
00:03 bhughes search for other commits by this committer
security/vuxml: document Node.js February 2019 Security Releases

https://nodejs.org/en/blog/vulnerability/february-2019-security-releases/

Sponsored by:	Miles AS
Original commitRevision:494469 
Saturday, 2 Mar 2019
10:29 joneum search for other commits by this committer
Document vulnerability in www/mybb

Sponsored by:	Netzkommune GmbH
Original commitRevision:494381 
Friday, 1 Mar 2019
08:57 madpilot search for other commits by this committer
Document new asterisk vulnerability.

Security:	CVE-2019-7251
Original commitRevision:494243 
Wednesday, 27 Feb 2019
07:33 brnrd search for other commits by this committer
security/vuxml: Update OpenSSL 1.0.2r entry
Original commitRevision:494030 
Sunday, 24 Feb 2019
19:59 kwm search for other commits by this committer
Document webkit-gtk CVE's

Security:	CVE-2019-6212, CVE-2019-6215, CVE-2019-6216, CVE-2019-6217, \
		CVE-2019-6226, CVE-2019-6227, CVE-2019-6229, CVE-2019-6233, \
		CVE-2019-6234.
Original commitRevision:493804 
Friday, 22 Feb 2019
17:58 pi search for other commits by this committer
security/vuxml: dokument rdesktop < 1.8.4 vulnerabilities

PR:		235885, 229029
Original commitRevision:493578 
Thursday, 21 Feb 2019
19:49 romain search for other commits by this committer
Document sysutils/puppetserver* vulnerabilities.

PuppetServer bundles Bouncy Castle, so add affected ports to the Bouncy Castle
entry.

sysutils/puppetserver is EOL and will likely never get a fix;
sysutils/puppetserver5 may get fixed in a future release of the 5.x branch;
sysutils/puppetserver6 was fixed in the latest release.

With hat:	puppet
Original commitRevision:493527 
14:45 acm search for other commits by this committer
- Add drupal8 vulnerability entry
Original commitRevision:493506 
Wednesday, 20 Feb 2019
10:13 brnrd search for other commits by this committer
security/vuxml: Document announced OpenSSL vulnerability

 - To be updated with more specifics on 2019-02-26
Original commitRevision:493418 
Friday, 15 Feb 2019
15:06 novel search for other commits by this committer
Document mail/msmtp certificate verification issue
Original commitRevision:493001 
Wednesday, 13 Feb 2019
11:27 cmt search for other commits by this committer
fix firefox-esr PORTEPOCH in latest entry

Submitted by:	jbeich
Original commitRevision:492852 
11:09 cmt search for other commits by this committer
add more mozilla products to latest entry

https://www.mozilla.org/en-US/security/advisories/mfsa2019-05/
(same CVEs as mfsa2019-04, so not creating another entry)
Original commitRevision:492847 
09:57 cmt search for other commits by this committer
document firefox vulnerabilities

https://www.mozilla.org/en-US/security/advisories/mfsa2019-04/
Original commitRevision:492841 
Tuesday, 12 Feb 2019
15:39 jkim search for other commits by this committer
Document the latest Flash Player vulnerability.

https://helpx.adobe.com/security/products/flash-player/apsb19-06.html
Original commitRevision:492788 
Monday, 11 Feb 2019
19:11 sunpoet search for other commits by this committer
Fix r492723 for the name of NVD report
Original commitRevision:492731 
18:59 sunpoet search for other commits by this committer
Update openjpeg status

There were 5 vulnerabilities in openjpeg and 4 of them are fixed.
The current status  is described in [1] as follows:
- CVE-2017-17479 and CVE-2017-17480 were fixed in r477112.
- CVE-2018-5785 was fixed in r480624.
- CVE-2018-6616 was fixed in r489415.
- CVE-2018-5727 is not fixed yet.

Though I keep committing fixes and updating the status, it does not show in the
"pkg audit" result. Users have to follow the link but apparently few people
would do that. Therefore, I got mails asking if the CVEs are fixed, etc.

I don't know if there's a better way to handle this condition (partly fixed over
several months). Instead of removing fixed CVEs from vuln.xml, I decided to add
a new entry (5efd7a93-2dfb-11e9-9549-e980e869c2e9) which is split from the old
entry (11dc3890-0e64-11e8-99b0-d017c2987f9a). It should be clearer for users if
they only read the "pkg audit" result.

[1] https://www.vuxml.org/freebsd/11dc3890-0e64-11e8-99b0-d017c2987f9a.html
Original commitRevision:492723 
00:11 feld search for other commits by this committer
Document FreeBSD-SA-19:02.fd
Original commitRevision:492661 
00:10 feld search for other commits by this committer
Document FreeBSD-SA-19:01.syscall
Original commitRevision:492660 
Sunday, 10 Feb 2019
18:02 tcberner search for other commits by this committer
Document kf5-kauth vulnerability.
Original commitRevision:492622 
Friday, 8 Feb 2019
01:12 osa search for other commits by this committer
Update versions range for recent unit vulnerability.
Original commitRevision:492404 
01:04 osa search for other commits by this committer
Document unit vulnerability.
Original commitRevision:492402 
Thursday, 7 Feb 2019
23:14 sunpoet search for other commits by this committer
Document curl vulnerability
Original commitRevision:492400 
Wednesday, 6 Feb 2019
09:10 mfechner search for other commits by this committer
Document gitlab-ce vulnerability.
Original commitRevision:492295 
Tuesday, 5 Feb 2019
14:52 ler search for other commits by this committer
mail/dovecot: update reporter for latest vuln
Original commitRevision:492246 
14:39 ler search for other commits by this committer
mail/dovecot: Suitable client certificate can be used to login as other user

update vuxml
Original commitRevision:492242 
Saturday, 2 Feb 2019
21:55 sunpoet search for other commits by this committer
Document typo3 vulnerability

PR:		235187, 235188
Original commitRevision:492007 
01:26 jrm search for other commits by this committer
security/vuxml: Document Gitea < 1.7.1 vulnerabilities

PR:		235399
Submitted by:	stb@lassitu.de (www/gitea maintainer)
Original commitRevision:491910 
Thursday, 31 Jan 2019
19:36 matthew search for other commits by this committer
Document vulnerability addressed by release 0.06 of p5-Email-Address-List

Unfortunately there is very little real description of the
vulnerability available, other than what is in the changelog.  Even
the CVE number only leads to a page saying the number is reserved.
Original commitRevision:491756 
17:42 mfechner search for other commits by this committer
Documented multiple vulnerabilities for www/gitlab-ce.
Original commitRevision:491741 
Wednesday, 30 Jan 2019
11:37 bhughes search for other commits by this committer
security/vuxml: document vulnerabilities in net/turnserver

Sponsored by:	Miles AS
Original commitRevision:491623 
Tuesday, 29 Jan 2019
17:18 jbeich search for other commits by this committer
security/vuxml: mark firefox < 65 as vulnerable
Original commitRevision:491586 
Monday, 28 Jan 2019
16:53 swills search for other commits by this committer
Document powerdns-recursor issue

PR:		235113
Submitted by:	Ralf van der Enden <tremere@cainites.net>
Original commitRevision:491493 
Sunday, 27 Jan 2019
19:58 sunpoet search for other commits by this committer
Update py-requests entry

Reference:	https://lists.freebsd.org/pipermail/svn-ports-head/2019-January/198601.html
Original commitRevision:491395 
15:14 brnrd search for other commits by this committer
security/vuxml: Document recent MySQL vulnerabilities

 - 5.5 branch see https://mariadb.com/kb/en/library/mariadb-5563-release-notes/
Original commitRevision:491356 
09:58 tcberner search for other commits by this committer
security/vuxml: Document security/botan2 vulnerability

PR:		234938
Submitted by:	Ralf van der Enden <tremere@cainites.net> (maintainer)
Original commitRevision:491336 
09:19 matthew search for other commits by this committer
Document PMASA-2019-1 and PMSA-2019-2 security advisories: Arbitrary
file disclosure and SQL injection attacks.
Original commitRevision:491330 
Saturday, 26 Jan 2019
10:54 joneum search for other commits by this committer
Add entry for www/gitea

PR:		235140
Sponsored by:	Netzkommune GmbH
Original commitRevision:491264 
09:49 koobs search for other commits by this committer
security/vuxml: Add libzmq4 -- Remote Code Execution Vulnerability

PR:	230575
Original commitRevision:491255 
Wednesday, 23 Jan 2019
15:10 zi search for other commits by this committer
Fix invalid package name in previous commit for
4af3241d-1f0c-11e9-b4bd-d43d7eed0ce2
Original commitRevision:491044 
14:37 joneum search for other commits by this committer
Add entry for www/apache24

Sponsored by:	Netzkommune GmbH
Original commitRevision:491040 
12:48 lev search for other commits by this committer
 Add CVE-2018-11803 for www/mod_dav_svn.
Original commitRevision:491034 
Tuesday, 22 Jan 2019
12:32 gjb search for other commits by this committer
Attempt to fix vuxml build.

Sponsored by:	The FreeBSD Foundation
Original commitRevision:490941 
10:44 koobs search for other commits by this committer
security/vuxml: Add www/py-requests: Information disclosure vulnerability
Original commitRevision:490936 
Sunday, 20 Jan 2019
01:05 ler search for other commits by this committer
security/vuxml: Document joomla 3 vulnerabilities.
Original commitRevision:490767 
Saturday, 19 Jan 2019
20:37 acm search for other commits by this committer
- Add drupal7 and drupal8 vulnerability entry
Original commitRevision:490737 
Friday, 18 Jan 2019
22:39 danilo search for other commits by this committer
Document helm security advisory
Original commitRevision:490676 
Thursday, 17 Jan 2019
00:14 mfechner search for other commits by this committer
Documented gitlab security vulnerability.
Original commitRevision:490522 
Wednesday, 16 Jan 2019
17:43 lwhsu search for other commits by this committer
Document Jenkins Security Advisory 2019-01-16

Sponsored by:	The FreeBSD Foundation
Original commitRevision:490495 
Tuesday, 15 Jan 2019
12:20 swills search for other commits by this committer
Document py-matrix-synapse issue

PR:		234828
Submitted by:	Sascha Biberhofer <ports@skyforge.at> (with slight editing)
Original commitRevision:490365 
Thursday, 10 Jan 2019
18:59 dbaio search for other commits by this committer
security/vuxml: Document irc/irssi issue

Security:	CVE-2019-5882

PR:		234798
Original commitRevision:489887 
Sunday, 6 Jan 2019
19:30 riggs search for other commits by this committer
Document out-of-bounds vulnerability in net/uriparser < 0.9.1

Reported by:	sebastian@pipping.org (via e-mail)
Original commitRevision:489524 
16:55 swills search for other commits by this committer
Document gitea issue

PR:		234659
Submitted by:	stb@lassitu.de
Original commitRevision:489511 
Saturday, 5 Jan 2019
23:00 sunpoet search for other commits by this committer
Update openjpeg status
Original commitRevision:489417 
13:20 cpm search for other commits by this committer
Document new vulnerability in www/chromium < 71.0.3578.98

Obtained
from:	https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop_12.html
Original commitRevision:489333 
13:10 cpm search for other commits by this committer
Document new vulnerabilities in www/chromium < 71.0.3578.80

Obtained
from:	https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Original commitRevision:489329 
08:09 wen search for other commits by this committer
- Documented security vulnerability of Django
Original commitRevision:489303 
Wednesday, 2 Jan 2019
09:03 mfechner search for other commits by this committer
Documented several gitlab-ce security vulnerabilities.

Approved by:	mentors (implicit)
Original commitRevision:489066 
Wednesday, 26 Dec 2018
21:05 swills search for other commits by this committer
Document gitea issue
Original commitRevision:488443 
16:09 rodrigo search for other commits by this committer
Add entry for archivers/rpm4 security isssue on 4.14.2
Original commitRevision:488403 
16:04 tijl search for other commits by this committer
Update handbrake entries now that 1.2.0 has been released.

PR:		234322
Submitted by:	Nei Teng  You Yi Lang  <naito.yuichiro@gmail.com> (maintainer)
Original commitRevision:488402 
Saturday, 22 Dec 2018
07:42 mfechner search for other commits by this committer
Documented security vulnerability for gitlab-ce.

Approved by:	mentors (implicit)
Original commitRevision:488071 
Thursday, 20 Dec 2018
14:50 girgen search for other commits by this committer
Add vuxml entry for shibboleth-sp
Original commitRevision:487884 
09:38 dch search for other commits by this committer
Document databases/couchdb2 and databases/couchdb vulnerability

Approved by:	jrm (mentor)
Security:	CVE-2018-17188
Security:	see http://docs.couchdb.org/en/stable/cve/2018-17188.html
Differential Revision:	https://reviews.freebsd.org/D18498
Original commitRevision:487870 
01:15 leres search for other commits by this committer
Mark bro < 2.6.1 as vulnerable as per:

    https://www.bro.org/download/NEWS.bro.html

The issue is a remote code execution vulnerability in the bundled
sqlite ("Magellan").

Reviewed by:	ler (mentor)
Approved by:	ler (mentor)
Differential Revision:	https://reviews.freebsd.org/D18615
Original commitRevision:487821 
Wednesday, 19 Dec 2018
21:15 feld search for other commits by this committer
Document FreeBSD-SA-18:15.bootpd
Original commitRevision:487817 
Saturday, 15 Dec 2018
15:03 joneum search for other commits by this committer
Document wordpress issues

Sponsored by:	Netzkommune GmbH
Original commitRevision:487518 
Friday, 14 Dec 2018
13:29 tijl search for other commits by this committer
HTML encode < and > and fix the formatting of the latest typo3 entry.
Original commitRevision:487432 

Number of commits found: 6271 (showing only 100 on this page)

[First Page]  «  4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14  »  [Last Page]