aboutsummaryrefslogtreecommitdiffstats
path: root/security/vuxml/vuln.xml
Commit message (Expand)AuthorAgeFilesLines
* - Document sudo privilege escalation vulnerability when usingwxs2010-03-021-0/+40
* Attempt to properly take care of the ooo3 -RC and -devel ports too (doh!)nox2010-03-011-0/+3
* - Document thunderbird3 vulnerabilitiesbeat2010-02-281-0/+5
* Document openoffice -- multiple vulnerabilitiesnox2010-02-271-0/+50
* - Document mozilla -- multiple vulnerabilitiesbeat2010-02-181-0/+51
* Document lighttpd remote DoS vulnerability.delphij2010-02-171-0/+30
* Update www/squid and www/squid30 to address Squid HTCP Packet Processingdelphij2010-02-151-0/+31
* Document linux-flashplugin -- multiple vulnerabilities.nox2010-02-141-0/+36
* Add CVE-2010-0414 and CVE-2010-0422 for gnome-screensaver.kwm2010-02-131-0/+34
* Fix range for fetchmail CVE-2010-0562.mandree2010-02-121-2/+1
* Add CVE-2010-0562 entry for mail/fetchmail.mandree2010-02-121-0/+35
* Document wireshark lwres buffer overflow vulnerability.delphij2010-02-101-0/+32
* Document "otrs" - SQL injection.skv2010-02-091-0/+34
* - add the rest of the apache 1.3.x packages to the listpgollucci2010-02-041-2/+44
* - document chunk-size integer overflow in apache 1.3.xpgollucci2010-02-041-0/+32
* - remove extraneou '>' as reported by make tidypgollucci2010-02-041-1/+1
* - Mark squid30 now as safemiwi2010-02-031-1/+1
* - Update 296ecb59-0f6b-11df-8bab-0019996bc1f7 entry and makr squid3* as safemiwi2010-02-021-2/+3
* Security patch for Squid advisory 2010:1, denial of service.delphij2010-02-021-0/+31
* Document "bugzilla" - information leak.skv2010-02-021-0/+33
* - Correct fixed version from previous entrymiwi2010-01-291-1/+1
* - Document irc-ratbox -- multiple vulnerabilitiesmiwi2010-01-291-0/+36
* - Document thunderbird3 vulnerabilitiesbeat2010-01-221-0/+5
* Document dokuwiki multiple vulnerabilities.delphij2010-01-191-0/+34
* - Added entry for multiple vulnerabilities in www/zend-frameworkglarkin2010-01-141-5/+58
* Document powerdns-recursor multiple vulnerabilities.delphij2010-01-091-0/+33
* Document pear-Net_Ping and pear-Net_Traceroute arbitrary command executiondelphij2010-01-051-0/+37
* Bump copyright year to 2010erwin2010-01-031-1/+1
* - Document drupal -- multiple cross-site scriptingmiwi2009-12-261-0/+38
* - Document sysutils/fuser privileges check vulnerability.stas2009-12-221-0/+26
* Document monkey remote DoS vulnerability.delphij2009-12-221-0/+30
* - Fix a typo (s/opensll/openssl)miwi2009-12-211-1/+2
* Document php multiple vulnerabilities.delphij2009-12-181-0/+51
* Document PostgreSQL multiple vulnerabilities.delphij2009-12-171-0/+52
* Add tptest pwd remote buffer overflow vulnerability.delphij2009-12-171-0/+29
* - Document mozilla -- multiple vulnerabilitiesmiwi2009-12-161-0/+61
* Make the problem more visible by choosing a more descriptive subject.delphij2009-12-151-1/+2
* Document freeradius remote packet of death exploit (CVE 2009-3111)delphij2009-12-151-0/+35
* - Mark Seamonkey 2.0 as safebeat2009-12-151-1/+2
* - Mark linux-firefox-devel as safebeat2009-12-131-16/+14
* - Fix buildmiwi2009-12-121-1/+0
* - Document pligg -- Cross-Site Scripting and Cross-Site Request Forgerywen2009-12-121-0/+40
* - Document piwik -- php code executionmiwi2009-12-111-0/+32
* - Fix previous entrys (formating etc)miwi2009-12-111-22/+22
* - Document dovecot insecure directory permissionswxs2009-12-101-0/+30
* Document linux-flashplugin -- multiple vulnerabilities.nox2009-12-101-0/+43
* - Document ruby 1.9.1 heap overflow vulnerability.stas2009-12-101-0/+28
* Document session fixation vulnerability in RequestTracker < 3.8.6skreuzer2009-12-091-0/+31
* - Add two CVE entries for expat2.kuriyama2009-12-081-0/+60
* - Document opera -- multiple vulnerabilitiesmiwi2009-12-021-0/+37
* Fix the libtool entry to include 2.2.6a as vulnerable.kwm2009-11-291-1/+1
* Document libtool vulnerability.kwm2009-11-291-0/+28
* - Cleanup (whitespaces/tabs)miwi2009-11-261-4/+4
* document: libvorbis -- multiple vulnerabilitiesnaddy2009-11-251-0/+31
* Document "bugzilla" - information leak.skv2009-11-241-0/+33
* - Report a XSS vulnerability in net-mgmt/cacti portsem2009-11-231-0/+27
* - fix german wordpress namemiwi2009-11-141-1/+1
* - Document wordpress -- multiple vulnerabilitiesmiwi2009-11-141-0/+41
* Mark php5-gd 5.2.11_2 as safe.delphij2009-11-101-2/+2
* - Note that CVE-2009-3546 has been fixed in graphics/gd.wxs2009-11-091-1/+2
* - Fix previous commitmiwi2009-11-061-2/+2
* - Document HTML-Parser denial of servicejadawin2009-11-061-0/+30
* Document remote buffer overflow vulnerability in gd.delphij2009-11-061-0/+41
* Document typo3 multiple vulnerabilities.delphij2009-11-061-0/+40
* Add an entry for VideoLAN-SA-0901, about multimedia/vlc.thierry2009-11-041-1/+30
* - Document KDE -- multiple vulnerabilitiesmiwi2009-11-031-0/+47
* - Fix previous entrymiwi2009-10-311-4/+5
* Add two opera vulnerabilitiesitetcu2009-10-311-0/+34
* - Fix latest entrysmiwi2009-10-301-15/+24
* Document vulnerability in net-p2p/ctorrent < 3.3.2_2 (CVE-2009-1759).flz2009-10-291-0/+34
* - Fix linux-opera vuxml entry (it uses different version numbering scheme) [1]stas2009-10-291-2/+9
* - Document mozilla -- multiple vulnerabilitiesbeat2009-10-281-0/+79
* - Fix discovery date of a recent entrygabor2009-10-251-1/+1
* - Document elinks < 0.11.4 buffer overflow vulnerability.stas2009-10-251-0/+33
* Add CVE reference provided by author via maintainer for the squidguarddelphij2009-10-231-0/+2
* Apply vendor fixes 20091015 and 20091019 to fix multiple vulnerabilitiesdelphij2009-10-231-0/+41
* - Add an entry for Xpdf -- Multiple Vulnerabilities.araujo2009-10-201-0/+31
* - Document django -- denial-of-service attacklwhsu2009-10-171-0/+46
* - Document phpmyadmin -- XSS and SQL injection vulnerabilitiesmiwi2009-10-141-0/+34
* - Document php5 multiple security vulnerabilities.wxs2009-10-131-0/+33
* - Document virtualbox -- privilege escalationmiwi2009-10-071-0/+29
* Add FreeBSD-SA-09:14.devfs to the VuXML list.remko2009-10-061-0/+39
* Add FreeBSD-SA-09:13.pipe to the VuXML list.remko2009-10-061-0/+40
* - linux-f10-pango is affected by 4b172278-3f46-11de-becb-001cc0377035 too.stas2009-10-011-1/+2
* - Document mybb -- multiple vulnerabilitiesmiwi2009-09-301-0/+34
* - Document drupal -- Multiple Vulnerabilitiesmiwi2009-09-231-0/+53
* - Rework latest horde-base entry (ee23aa09-a175-11de-96c0-0011098ad87f)miwi2009-09-221-3/+15
* Fix a formatting issue.cy2009-09-201-3/+3
* Fix build.delphij2009-09-201-1/+4
* Document a security problem in fwbuilder/libfwbuilder 3.0.4 - 3.0.6.cy2009-09-201-0/+25
* Document "bugzilla" - two SQL injections, sensitive data exposure.skv2009-09-171-0/+35
* Adding an entry for three vulnerabilities fixed in the latest Hordethierry2009-09-151-0/+25
* - Fix formatting.stas2009-09-151-8/+6
* Document nginx DoS condition.wxs2009-09-151-0/+35
* Add cvename and bid for cyrus-imapd potential buffer overflowume2009-09-141-1/+4
* Add ikiwiki vulnerability.brix2009-09-141-0/+28
* - Cleanup previous commitmiwi2009-09-131-4/+4
* - Add xapian-omega cross-scripting vulnerabilitybrix2009-09-131-0/+28
* - Document mozilla firefox -- Multiple Vulnerabilitiesmiwi2009-09-111-0/+49
* Fix xml broke by my previous commit.ume2009-09-091-1/+1
* Document cyrus-imapd potential buffer overflow vulnerability in Sieve.ume2009-09-091-0/+27
* - Document silc-toolkit format string vulnerabilities. Unfortunately littlewxs2009-09-091-0/+28
* - Mark seamonkey as safemiwi2009-09-041-1/+4
* - Update latest Opera entry,miwi2009-09-041-3/+4
* - Fix vuxml buildjadawin2009-09-041-2/+0
* - Fix vuxml buildjadawin2009-09-041-2/+3
* Add an atry for opera < 10.00itetcu2009-09-041-0/+38
* - Fix cvenamesmiwi2009-09-021-2/+2
* - Document dnsmasq -- TFTP server remote code injection vulnerabilitymiwi2009-09-021-0/+34
* - I cannot confirm these vulns can be affected to 1.3.x and 2.0.xkuriyama2009-08-251-8/+8
* Add apache-2.2.12 fixes.kuriyama2009-08-251-0/+35
* - Mark thunderbird 2.0.0.23 and higher as safebeat2009-08-221-2/+2
* - Document pidgin, libpurple, and finch memory corruption.wxs2009-08-211-0/+38
* - Document NUL byte problem in gnutls and gnutls-develwxs2009-08-171-0/+80
* - memcached -- memcached stats maps Information Disclosure Weaknessmnag2009-08-171-0/+31
* - Update latest wordpress entrymiwi2009-08-131-1/+7
* Document remote admin password reset vulnerability in wordpress <= 3.8.3skreuzer2009-08-121-0/+34
* - Document fetchmail -- improper SSL certificate subject verificationamdmi32009-08-111-0/+36
* Fix typo in affected version number for vidskreuzer2009-08-111-2/+2
* - Fix improper formatting reported by miwiskreuzer2009-08-081-1/+3
* Document com_mailto Timeout Issue in www/joomla15skreuzer2009-08-081-0/+27
* Cleanup whitespace and XML format using 'make tidy' and a bit manualsimon2009-08-081-61/+48
* Various affects fixes to the last 3 Mozilla/Firefox entries to make thensimon2009-08-071-21/+17
* - Update previous subversion entry,miwi2009-08-071-2/+3
* - Fix latest firefox entry.miwi2009-08-071-3/+4
* Document subversion -- heap overflow vulnerability.simon2009-08-071-0/+39
* Add a few CVE names to the 'squid -- several remote denial of servicesimon2009-08-061-1/+3
* Document bugzilla -- product name information leak.simon2009-08-061-0/+30
* - Mark squid 3.1.0.12 as safemiwi2009-08-051-1/+2
* - Document mozilla -- multiple vulnerabilitiesmiwi2009-08-051-0/+63
* - Add bind9-sdb-ldap and bind9-sdb-postgresql to recent BIND DoS.wxs2009-08-051-0/+6
* - Document silc-client and silc-irssi-plugin format string vulnerability.wxs2009-08-051-0/+27
* Mark mail/squirrelmail-multilogin-plugin as FORBIDDEN and add thethierry2009-08-021-0/+28
* - White space fixes and correct the entry date inwxs2009-08-011-22/+22
* s/package/system/ for vid fbc8413f-2f7a-11de-9a3f-001b77d09812.wxs2009-08-011-2/+2
* - Document BIND DoS in base and ports.wxs2009-08-011-0/+48
* - Close tagmiwi2009-07-301-1/+1
* - Document Mono XML Signature HMAC Truncation Spoofingmiwi2009-07-301-0/+30
* Document squid remote denial of service vulnerabilities.delphij2009-07-281-0/+34
* Fix security advsory with patches from Ubuntu project.jpaetzel2009-07-221-1/+2
* - Fix a typomiwi2009-07-171-1/+1
* - Document firefox35 -- corrupt JIT state after deep return from native functionmiwi2009-07-171-0/+32
* - Document isc-dhcp*-client stack overflow.wxs2009-07-161-0/+34
* - Tweak nagios version information a bit for the command injectionwxs2009-07-141-2/+2
* - Document drupal -- multiple vulnerabilitiesmiwi2009-07-141-0/+58
* - Mark linux-firefox 3.0.11 and higher as safebeat2009-07-121-2/+13
* - Document remote command execution in net-mgmt/nfsenwxs2009-07-031-0/+27
* - Add syslog-ng package to the list of vulnerable versions for the chrootwxs2009-07-031-0/+5
* - Add newly created CVE for nagios command injection vulnerability.wxs2009-07-011-0/+10
* Document phpMyAdmin XSS vulnerabilitydelphij2009-07-011-0/+28
* - Document nagios command injection vulnerability.wxs2009-06-301-0/+34
* - s/secunia reports/Secnuia reports/wxs2009-06-251-30/+30
* - Document tor-devel DNS resolution issue.wxs2009-06-231-1/+28
* - Document cscope -- multiple buffer overflowsmiwi2009-06-171-0/+32
* - Document cscope -- buffer overflowmiwi2009-06-171-7/+12
* - Fix a typo from previous commitmiwi2009-06-171-1/+24
* Document joomla -- multiple vulnerabilitiesskreuzer2009-06-171-0/+41
* - Document pidgin -- multiple vulnerabilitiesmiwi2009-06-171-0/+49
* - Document git-daemon DoS.wxs2009-06-151-0/+31
* - Fix the latest ruby entry: 1.9 branch is not vulnerable.stas2009-06-131-1/+1
* - Document ruby denial of sevice vulnerability in BigDecimal.stas2009-06-131-0/+36
* - Fix firefox3 version in da185955-5738-11de-b857-000f20797edebeat2009-06-121-1/+1
* - Document mozilla -- multiple vulnerabilitiesbeat2009-06-121-0/+77
* - Add some more cve to the previous entrymiwi2009-06-081-0/+2
* - Fix previous entrymiwi2009-06-081-10/+10
* Document DOS in apr-util xml(expat) processingpgollucci2009-06-081-0/+50
* Document dokuwiki local File Inclusion with register_globals on vulnerability.delphij2009-06-051-0/+34
* - Document openssl -- denial of service in DTLS implementationmiwi2009-05-311-0/+34
* - Document eggdrop -- denial of service vulnerabilitymiwi2009-05-311-0/+31
* - Document wireshark -- Denial of Service in the PCNFSD dissectormiwi2009-05-311-0/+35
* - Add more infos for libsndfile entrymiwi2009-05-311-0/+3
* - Document libsndfile -- multiple vulnerabilitiesmiwi2009-05-311-0/+33
* - Document slim -- local disclosure of X authority magic cookiemiwi2009-05-311-0/+34
* - Cleanup previous entrymiwi2009-05-231-2/+4
* Unbreak file by removing double <vuxml> tag.simon2009-05-231-1/+1
* Add CVE information for NTP stack overflow.cy2009-05-231-0/+28
* - Fix 5ed2f96b-33b7-4863-8c6b-540d22344424miwi2009-05-231-2/+2
* - Bump modified date for previous commit.miwi2009-05-231-0/+1
* - Add CVE information for nsd overflow.wxs2009-05-221-1/+2
* - Document imap-uw -- University of Washington IMAP c-client Remote Formatpav2009-05-211-0/+29
* - Document dns/nsd and dns/nsd2 one-byte overflow (both are already fixedwxs2009-05-201-0/+33
* Add entries of libxine vulnerabilities fixed in version 1.1.16.2 and 1.1.16.3.nobutaka2009-05-171-0/+77
* - Document php -- ini database truncation inside dba_replace() functionmiwi2009-05-171-0/+34
* - Document libwmf -- embedded GD library Use-After-Free vulnerabilitymiwi2009-05-171-0/+35
* - Document libwmf -- Integer Overflow Vulnerabilitymiwi2009-05-171-0/+34
* - Document moinmoin -- cross-site scripting vulnerabilitiesmiwi2009-05-161-1/+31
* - Rework previus entrymiwi2009-05-161-7/+9
* - Document mod_perl -- cross site scripting in Apache::Statuspgollucci2009-05-161-0/+33
* - Small cleanupmiwi2009-05-161-4/+6
* - Fix formatingmiwi2009-05-161-17/+17
* Document drupal -- cross-site scripting vulnerability.delphij2009-05-161-0/+47
* - Document cyrus-sasl -- buffer overflow vulnerabilityume2009-05-151-0/+29
* - Document moinmoin -- multiple cross site scripting vulnerabilitiesmiwi2009-05-131-0/+37
* - Document ghostscript8 -- Buffer Overflow Vulnerabilitymiwi2009-05-131-0/+34
* - Cleanupmiwi2009-05-131-47/+56
* - Added a referece to the latest pango entry (4b172278-3f46-11de-becb-001cc03...miwi2009-05-131-1/+3
* - Document pango buffer overflow vulnerability.stas2009-05-131-0/+36
* Document the recent Wireshark vulnerabilities.marcus2009-05-101-0/+42
* - Add CVE entry for quagga vulnerability.wxs2009-05-071-0/+2
* - add CUPS 1.3.10dinoex2009-05-071-0/+52
* - add SA-09:08.openssldinoex2009-05-071-0/+38
* - Document quagga DoS.wxs2009-05-061-0/+29
* - Mark flock 2.0 as safebeat2009-05-051-1/+4
* - Cleanup previous entrymiwi2009-05-051-7/+10
* - Document openfire -- Password Changes Security Bypassgahr2009-05-041-0/+32
* - Document drupal -- cross site scriptingmiwi2009-05-011-0/+48
* - CVE-2007-3387 has been fixed in pdftohtml 0.39_3.stas2009-04-291-2/+2
* - Document mozilla -- multiple vulnerabilitiesmiwi2009-04-221-0/+78
* Document the recent poppler vulnerabilities fixed in 0.10.6.marcus2009-04-191-0/+26
* - Rework previus entry (xpdf -- multiple vulnerabilities)miwi2009-04-191-9/+21
* - Document xpdf -- multiple vulnerabilitiesaraujo2009-04-191-0/+40
* - Document freetype2 -- multiple vulnerabilitiesmiwi2009-04-181-0/+37
* - Document ejabberd cross-site scripting vulnerability.wxs2009-04-181-0/+30
* - Document ziproxy -- Multiple HTTP Proxy HTTP Host Header Incorrect Relay Be...miwi2009-04-151-1/+35
* - Document phpmyadmin -- insufficient output sanitizing when generating confi...miwi2009-04-151-0/+30
* - Document drupal6-cck -- cross-site scriptingmiwi2009-04-111-0/+34
* - Document pivot-weblog -- file deletion vulnerabilitymiwi2009-03-281-0/+36
* Fix the roundcube version of CVE-2009-0413, should be 0.2.1,1 and not 0.2.1.mat2009-03-261-1/+2
* Document phpmyadmin: insufficient output sanitizing when generatingdelphij2009-03-251-0/+31
* - Update 8e8b8b94-7f1d-11dd-a66a-0019666436c2 (www/rubygem-rails) now securemiwi2009-03-231-1/+2
* - Fix daf045d7-b211-11dd-a987-000c29ca8953miwi2009-03-231-6/+4
* - Update zabbix entry is now securemiwi2009-03-231-2/+3
* - Fix spellingmiwi2009-03-231-1/+1
* - Document amarok -- multiple vulnerabilitiemiwi2009-03-231-0/+39
* - Fix portaudit buildmiwi2009-03-231-6/+9
* - Cleanup latest Wireshark entrymiwi2009-03-231-6/+3
* - Bump modified date for zope entrymiwi2009-03-231-1/+1
* - zope-2.7.9_2 securepav2009-03-231-1/+1
* Add an entry for Wireshark less than or equal to 1.0.5 pertaining tomarcus2009-03-231-0/+36
* - Mark *seamonkey as safemiwi2009-03-211-1/+1
* - Add CVE's referenc to 78f5606b-f9d1-11dd-b79c-0030843d3802miwi2009-03-211-0/+4
* - Mark mail/*thunderbird as safemiwi2009-03-211-2/+2
* - Added more references to the netatalkmiwi2009-03-191-1/+4
* - Small cleanupmiwi2009-03-181-7/+4
* - Document netatalk -- arbitrary command execution in papd daemonmiwi2009-03-181-0/+33
* - Fix discovery date from previous entrymiwi2009-03-171-1/+1
* - Document gstreamer-plugins-good -- multiple memory overflowsmiwi2009-03-171-0/+44
* - Document libsndfile -- CAF processing integer overflow vulnerabilitymiwi2009-03-171-0/+29
* - Fix roundcube entrymiwi2009-03-171-1/+1
* - Document ffmpeg -- 4xm processing memory corruption vulnerabilitymiwi2009-03-171-0/+34
* - Document roundcube -- webmail script insertion and php code injectionmiwi2009-03-171-0/+41
* - Document proftpd -- multiple sql injection vulnerabilitiesmiwi2009-03-171-0/+44
* - Fix a typomiwi2009-03-171-1/+1
* - Document zappix -- php frontend multiple vulnerabilitiesmiwi2009-03-171-0/+46
* - Document php-mbstring -- php mbstring buffer overflow vulnerabilitymiwi2009-03-171-0/+37
* - Document phppgadmin -- directory traversal with register_globals enabledmiwi2009-03-171-0/+32
* - Document opera -- multiple vulnerabilitiesmiwi2009-03-161-0/+32
* - Clean up latest curl entrymiwi2009-03-141-4/+4
* - Document epiphany -- untrusted search path vulnerabilitytabthorpe2009-03-121-0/+31
* - Document apache -- Cross-site scripting vulnerabilitytabthorpe2009-03-121-0/+33