Commit graph

641 commits

Author SHA1 Message Date
Christian Weisgerber
e31b579a93 Document remote buffer overflow in ftp/axel. 2005-04-17 15:34:43 +00:00
Simon L. B. Nielsen
2bbbbc938d Document firefox -- PLUGINSPAGE privileged javascript execution (also
from the < 1.0.3 batch).
2005-04-16 22:52:07 +00:00
Remko Lodder
7ce5f5f5eb Document jdk - jar directory traversal vulnerability.
Approved by:	simon
2005-04-16 22:35:09 +00:00
Simon L. B. Nielsen
c6463c5ae8 Document several mozilla/firefox issues. 2005-04-16 16:12:02 +00:00
Simon L. B. Nielsen
b8e8bd4784 Mark wget >= 1.10.a1 safe from the "wget -- multiple vulnerabilities"
entry.

Info provided by:	sf
2005-04-15 21:47:10 +00:00
Simon L. B. Nielsen
c666625667 Document openoffice -- DOC document heap overflow vulnerability. 2005-04-13 23:17:14 +00:00
Simon L. B. Nielsen
2a6230f941 Fix and document insecure temporary file handling in portupgrade.
Security:	CAN-2005-0610
Security:	http://vuxml.FreeBSD.org/22f00553-a09d-11d9-a788-0001020eed82.html
Approved by:	erwin (mentor), maintainer timeout
OK'ed by:	portmgr
Reviewed by:	nectar
2005-04-12 08:24:48 +00:00
Simon L. B. Nielsen
c5a9b3a376 Document three GAIM vulnerabilities. 2005-04-10 19:41:46 +00:00
Simon L. B. Nielsen
4ac987a82c Document an old PHP issue. 2005-04-10 18:47:06 +00:00
Simon L. B. Nielsen
63de08eab1 Document squid -- DoS on failed PUT/POST requests vulnerability.
Submitted by:	Devon H. O'Dell <dodell@offmyserver.com> (original version)
2005-04-10 10:22:18 +00:00
Pav Lucistnik
b1c64c078b - Fix closing tag on the entry I just touched.
Pointed out by:	still Chimera
Blaming:	too much bear earlier tonight
2005-04-09 20:42:03 +00:00
Pav Lucistnik
ecf039676f - Add <modified> to the entry I just touched
Prodded by:	Chimera
2005-04-09 20:38:37 +00:00
Pav Lucistnik
e22567b87a - CAN-2005-0133 is fixed in clamav-devel-20050408
PR:		ports/79688
Submitted by:	Renato Botelho <freebsd@galle.com.br>
2005-04-09 20:21:47 +00:00
Simon L. B. Nielsen
3325b65493 Bump modified date for entry modified last commit. 2005-04-05 20:57:06 +00:00
Hajimu UMEMOTO
f17f51ad0e add CVE name to latest vuln of Cyrus IMAPd. 2005-04-05 20:03:49 +00:00
Thierry Thomas
24b5ab2bb9 Add an entry for a XSS vulnerabilty fixed in horde-3.0.4. 2005-04-05 19:57:09 +00:00
Simon L. B. Nielsen
7e369a9d2b Document wu-ftpd -- remote globbing DoS vulnerability. 2005-04-04 20:06:01 +00:00
Simon L. B. Nielsen
08a1fddf90 Add CVE name to hashash entry. 2005-04-03 06:53:58 +00:00
Christian Weisgerber
7ce77e7525 Document hashcash format string vulnerability. 2005-04-02 23:15:17 +00:00
Simon L. B. Nielsen
3ea2a15c21 Document clamav -- zip handling DoS vulnerability.
Approved by:	portmgr (blanket, VuXML)
2005-03-26 20:49:39 +00:00
Jacques Vidrine
8fdf391a72 Document Wine information disclosure.
Based on an entry that was
Submitted by:	Devon H. O'Dell <dodell@offmyserver.com>
Approved by:	portmgr (blanket, VuXML)
2005-03-24 14:15:05 +00:00
Jacques Vidrine
ad6be0e3c8 Document the most serious of the recently disclosed
Mozilla/Firefox/Thunderbird vulnerabilities.

Based on entries that were
Submitted by:	Devon H. O'Dell <dodell@offmyserver.com>
Approved by:	portmgr (blanket, VuXML)
2005-03-24 14:08:28 +00:00
Jacques Vidrine
540824d2e8 Document Sylpheed buffer overflow.
Reminded by:	netchild
Approved by:	portmgr (blanket, VuXML)
2005-03-23 18:29:15 +00:00
Simon L. B. Nielsen
5b82e7ed54 Document xv -- filename handling format string vulnerability.
Approved by:	portmgr (implicit, VuXML)
2005-03-21 21:19:21 +00:00
Simon L. B. Nielsen
e551c99e0a Document kdelibs -- local DCOP denial of service vulnerability.
Approved by:	portmgr (implicit, VuXML)
2005-03-21 20:27:19 +00:00
Simon L. B. Nielsen
4b8ba5ca05 Mark grip port as fixed for recent vulnerability.
Requested by:	ahze
2005-03-18 19:16:10 +00:00
Simon L. B. Nielsen
9c13358c08 Document phpmyadmin -- increased privilege vulnerability. 2005-03-15 21:13:28 +00:00
Alexey Dokuchaev
15f66ab5b1 Note that recent Quake2-LNX is fixed. 2005-03-15 19:40:23 +00:00
Alex Dupre
2e4290eeb0 Recent mysql snapshot import fixed several vulnerabilities. 2005-03-15 14:27:01 +00:00
Simon L. B. Nielsen
566e20849d Document ethereal -- multiple protocol dissectors vulnerabilities. 2005-03-14 21:55:46 +00:00
Simon L. B. Nielsen
29d805dd40 Document "grip -- CDDB response multiple matches buffer overflow
vulnerability".
2005-03-14 20:19:29 +00:00
Simon L. B. Nielsen
f1996dbbb7 Update references for latest MySQL entry:
- Use bid tag for Bugtraq ID reference.
- Add CVE names.
2005-03-14 19:49:15 +00:00
Alex Dupre
09faa83406 Document multiple mysql remote vulnerabilities. 2005-03-14 15:16:35 +00:00
Thierry Thomas
c3c8132fc3 Add an entry about rxvt-unicode bufer overflow. 2005-03-13 10:31:19 +00:00
Simon L. B. Nielsen
2f4093a8ae Document two phpMyAdmin issues. 2005-03-08 22:52:18 +00:00
Simon L. B. Nielsen
098596aedb Document libexif -- buffer overflow vulnerability. 2005-03-08 21:26:23 +00:00
Jacques Vidrine
3b0cb09a6a Fix invalid date.
Noticed by:	Kang Liu <liukang@bjut.edu.cn>
2005-03-07 15:45:13 +00:00
Jacques Vidrine
6cec90d8a0 Add <modified> date for recent commit to phpbb vulnerability.
Forgotten by:	delphij

While here, add msgids for recent phpbb addition.
2005-03-06 17:06:32 +00:00
Xin LI
5092eea0da Document a low risk HTML injection (configuration bypass)
vulnerability [1] of phpBB.

(maintainer contacted and is preparing a fix)

[1] http://marc.theaimsgroup.com/?l=bugtraq&m=110987231502274
2005-03-05 15:53:41 +00:00
Xin LI
852b94cbf0 Add bugtraq bug ID for phpbb vulnerability.
Submitted by:	Kang LIU <liukang bjut edu cn>
2005-03-05 15:42:50 +00:00
Jacques Vidrine
3fbc94976e Document two phpnuke vulnerabilities, and a Linux RealPlayer
vulnerability.

Based on entries that were
Submitted by:	Devon H. O'Dell <dodell@sitetronics.com>
2005-03-04 18:14:28 +00:00
Simon L. B. Nielsen
27b0023153 - Document ImageMagick -- format string vulnerability.
- Fix typo on older tiff entry.
2005-03-03 22:20:45 +00:00
MANTANI Nobutaka
8a81c46428 Document the privilege escalation vulnerability in uim. 2005-03-02 13:17:24 +00:00
Jacques Vidrine
1f1453269f Fix typo in linux-tiff version number for
http://vuxml.freebsd.org/8f86d8b5-6025-11d9-a9e7-0001020eed82.html

Reported by:    Ian Moore <no-spam@swiftdsl.com.au>
2005-03-01 13:39:29 +00:00
Jacques Vidrine
8ec244ef06 Document lighttpd information disclosure bug.
This entry is based on one that was
Submitted by:	Devon H. O'Dell <dodell@offmyserver.com>
2005-03-01 13:23:52 +00:00
Jacques Vidrine
b511a32842 Fix typo in linux-tiff version number for
http://vuxml..freebsd.org/fc7e6a42-6012-11d9-a9e7-0001020eed82.html

Reported by:	Ian Moore <no-spam@swiftdsl.com.au>
2005-02-28 13:41:19 +00:00
Xin LI
ab9ba5a88f Document latest phpBB critical security vulnerabilities.
Submitted by:	Kang LIU <liukang bjut edu cn>
2005-02-28 10:48:53 +00:00
Jacques Vidrine
24627424e6 Correct the linux-tiff version number for several entries.
Reported by:	netchild
2005-02-28 03:42:01 +00:00
Simon L. B. Nielsen
3ab3a3220e Document curl -- authentication buffer overflow vulnerability. 2005-02-27 21:24:03 +00:00
Simon L. B. Nielsen
3ba6fcbd61 - Document cyrus-imapd -- multiple buffer overflow vulnerabilities. [1]
- Use bid tag for a reference in sup entry.

Advice from:	ume [1]
2005-02-27 20:34:17 +00:00