FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

nothing found there

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
10e1d580-d174-11e9-a87f-a4badb2f4699xymon-server -- multiple vulnerabilities

Japheth Cleaver reports:

Several buffer overflows were reported by University of Cambridge Computer Security Incident Response Team.


Discovery 2019-07-23
Entry 2019-09-07
xymon-server
lt 4.3.29

https://lists.xymon.com/archive/2019-July/046570.html
CVE-2019-13451
CVE-2019-13452
CVE-2019-13455
CVE-2019-13273
CVE-2019-13274
CVE-2019-13484
CVE-2019-13485
CVE-2019-13486
1c7cfd05-aaee-11e4-83b4-14dae9d210b8Xymon -- buffer overrun

Debian reports:

web/acknowledge.c uses a string twice in a format string, but only allocates memory for one copy.


Discovery 2014-09-28
Entry 2015-02-02
xymon-server
ge 4.3.4 lt 4.3.18

http://www.openwall.com/lists/oss-security/2015/01/31/4
https://security-tracker.debian.org/tracker/CVE-2015-1430
CVE-2015-1430
1cecd5e0-c372-11e5-96d6-14dae9d210b8xymon-server -- multiple vulnerabilities

J.C. Cleaver reports:

  • CVE-2016-2054: Buffer overflow in xymond handling of "config" command

  • CVE-2016-2055: Access to possibly confidential files in the Xymon configuration directory

  • CVE-2016-2056: Shell command injection in the "useradm" and "chpasswd" web applications

  • CVE-2016-2057: Incorrect permissions on IPC queues used by the xymond daemon can bypass IP access filtering

  • CVE-2016-2058: Javascript injection in "detailed status webpage" of monitoring items; XSS vulnerability via malformed acknowledgment messages


Discovery 2016-01-19
Entry 2016-02-09
xymon-server
lt 4.3.25

http://lists.xymon.com/pipermail/xymon/2016-February/042986.html
CVE-2016-2054
CVE-2016-2055
CVE-2016-2056
CVE-2016-2057
CVE-2016-2058