aboutsummaryrefslogtreecommitdiffstats
path: root/security/vuxml
Commit message (Expand)AuthorAgeFilesLines
* Correct a typo: s/lemote/remote/remko2005-07-101-1/+1
* Document the following vulnerabilities:remko2005-07-101-0/+159
* Document phppgadmin -- "formLanguage" local file inclusion vulnerability.simon2005-07-091-0/+34
* Document pear-XML_RPC -- information disclosure vulnerabilities.simon2005-07-091-0/+31
* Document ekg -- insecure temporary file creation.simon2005-07-091-0/+29
* Document bugzilla -- multiple vulnerabilities.simon2005-07-091-0/+40
* Document nwclient -- multiple vulnerabilities (old issues).simon2005-07-091-0/+41
* Add CAN reference to recent phpbb vulnerability.simon2005-07-071-0/+2
* Document acroread -- insecure temporary file creation.simon2005-07-071-0/+40
* Document two calmav vulnerabilities.simon2005-07-071-0/+87
* - Add FreeBSD-SA-05:16.zlib.simon2005-07-071-17/+51
* Document acroread -- buffer overflow vulnerability.simon2005-07-071-0/+41
* Document net-snmp -- remote DoS vulnerability.simon2005-07-061-0/+29
* Document cacti -- multiple vulnerabilities.simon2005-07-061-0/+63
* - Add another reference to bzip2 -- denial of service and permissionsimon2005-07-061-0/+68
* Document the following issues:hrs2005-07-031-0/+61
* Add certvu reference to kernel -- TCP connection stall denial of servicesimon2005-07-031-0/+2
* Add FreeBSD-SA-05:13.ipfw, FreeBSD-SA-05:14.bzip2, andsimon2005-06-301-0/+142
* Document ethereal -- multiple protocol dissectors vulnerabilities.simon2005-06-251-0/+131
* Document tor -- information disclosure.hrs2005-06-241-0/+29
* Document linux-realplayer -- RealText parsing heap overflow.hrs2005-06-241-0/+31
* Document ruby -- arbitrary command execution on XMLRPC server.hrs2005-06-231-0/+33
* - net/cacti - potential SQL injection and cross site scripting attackssem2005-06-211-0/+24
* Document three opera issues.simon2005-06-211-0/+109
* Document sudo -- local race condition vulnerability.simon2005-06-211-0/+34
* Add another reference to the latest tcpdump issue.simon2005-06-211-0/+2
* - Add entry for trac -- file upload/download vulnerability.simon2005-06-211-10/+61
* - razor-agents DoS vulnerabilitiessem2005-06-201-0/+29
* Fix year in <discovery> and <entry>.hrs2005-06-191-2/+2
* Document SpamAssassin -- Denial of service vulnerability.hrs2005-06-191-0/+36
* Document squirrelmail -- Several cross site scripting vulnerabilities.hrs2005-06-191-0/+33
* Document acroread -- XML External Entity vulnerability.hrs2005-06-191-0/+29
* Use standard topic format for gzip vulnerability.simon2005-06-181-1/+2
* Document FreeBSD-SA-05:11.gzip.simon2005-06-181-0/+55
* Document SA-05:10.tcpdump.simon2005-06-181-0/+41
* Document two vulnerabilities in Gaim.simon2005-06-181-0/+62
* Document an older, more serious gallery vulnerability.nectar2005-06-181-0/+25
* Document XSS vulnerabilities in gallery.nectar2005-06-181-0/+30
* Document KDE kstars vulnerability.nectar2005-06-181-0/+40
* Document fd_set overruns reported by 3APA3A.nectar2005-06-181-0/+49
* Document leafnode -- denial of service vulnerability.simon2005-06-091-0/+33
* Document a directory traversal issue in older GForge versions.nectar2005-06-041-0/+30
* Document an authentication bypass vulnerability in imap-uw.nectar2005-06-041-0/+27
* Document squid denial-of-service vulnerabilities.nectar2005-06-041-0/+29
* Document a remote denial-of-service vulnerability in racoon.nectar2005-06-041-0/+27
* Document integer overflows in xli.nectar2005-06-041-0/+26
* Document arbitrary command execution vulnerabilities in xli andnectar2005-06-041-0/+35
* Add new CVE names for yamt entry.nectar2005-06-041-0/+2
* Correct and improve recent xli entry:nectar2005-06-041-5/+15
* Correct recently added yamt entry:nectar2005-06-041-6/+19
* Buffer overflow in xli.trhodes2005-06-031-0/+24
* Fix breakage I caused.trhodes2005-06-031-1/+1
* Note buffer overflows and directory transversal issues in audio/ymat.trhodes2005-06-031-0/+25
* Update entry for FreeStyle Wiki:nectar2005-06-021-6/+14
* Document vulnerabilities in XView library.nectar2005-06-021-0/+31
* document a vulnerability in xtrlocknectar2005-06-021-0/+27
* Document vulnerabilities reported in the Red Hat 7.1 libraries.nectar2005-06-021-0/+36
* Document squirrelmail vulnerabilities.nectar2005-06-021-0/+59
* correct version number for mailman password generation issuenectar2005-06-011-1/+1
* Document vulnerability in set-user-ID sympa application.nectar2005-06-011-0/+28
* Another older mailman vulnerability, somewhat minornectar2005-06-011-0/+38
* Add year-old mailman vulnerability, that seems to not have beennectar2005-06-011-0/+32
* document Apache Jakarta Tomcat 5.x XSS issuenectar2005-06-011-0/+25
* Mark samba-2.2.12.j1.0beta1_2 as safe from "samba -- integer overflowsimon2005-05-291-1/+6
* - Update to 3.5.8 (including XSS problem fix).kuriyama2005-05-291-0/+28
* Remove a forgotten :.remko2005-05-221-1/+1
* Document the following issues:remko2005-05-221-0/+94
* Fix entry dates for latest squid entries.simon2005-05-201-5/+4
* Reword the cdrdao entry, this includes comments from Simon which i overlooked.remko2005-05-201-4/+4
* - Update Squid to 2.5.STABLE10pav2005-05-191-0/+58
* Document cdrdao -- unspecified privilege escalation vulnerability.remko2005-05-191-0/+28
* Document two gaim issues.simon2005-05-141-0/+69
* Add FreeBSD-SA-05:09.htt.nectar2005-05-141-0/+50
* $EDITOR should not be quoted. It might be "emacsclient -a vi" ornectar2005-05-131-1/+1
* MAINTAINER -> security@FreeBSD.orgnectar2005-05-131-1/+1
* Update some leafnode references.nectar2005-05-131-3/+45
* Document two new vulnerabilities in mozilla/firefox.simon2005-05-121-0/+183
* Document mozilla -- code execution via javascript: IconURL vulnerability.simon2005-05-121-0/+100
* Document some vulnerabilities in groff.okazaki2005-05-091-0/+55
* - gnu-radius exploitation was fixed in maintenance release 1.2.94sem2005-05-031-1/+2
* . Update the version for the jar(1) vulnerability so that 1.2.2p11_4 isglewis2005-05-031-2/+3
* Document sharutils -- unshar insecure temporary file creationremko2005-05-011-0/+30
* Document rsnapshot -- local privilege escalationremko2005-05-011-0/+31
* coppermine -- IP spoofing and XSS vulnerabilitybrooks2005-05-011-0/+35
* . Correct the range of vulnerable jdk14 ports for the jar(1) vulnerabilityglewis2005-04-291-2/+2
* Document ImageMagick -- ReadPNMImage() heap overflow vulnerability.simon2005-04-281-0/+30
* Bump modified date for last commit.simon2005-04-281-1/+2
* . Adjust ranges so that jdk-1.3.1p9_5 is no longer marked as vulnerable toglewis2005-04-281-2/+3
* Document mplayer & libxine -- MMS and Real RTSP buffer overflowsimon2005-04-261-0/+61
* Document some older vulnerabilities in GAIM.simon2005-04-261-0/+66
* Document kdewebdev -- kommander untrusted code execution vulnerability.simon2005-04-231-0/+33
* Fix a typo in the kdelibs - kimgio entry.remko2005-04-231-1/+1
* junkbuster -- heap corruption vulnerability and configuration modification vu...remko2005-04-231-0/+41
* Document kdelibs -- kimgio input validation errors.simon2005-04-221-0/+35
* Mark latest openoffice 1.1 as fixed wrt. openoffice -- DOC documentsimon2005-04-201-1/+2
* Document gld -- format string and buffer overflow vulnerabilitiesremko2005-04-191-0/+37
* Document remote buffer overflow in ftp/axel.naddy2005-04-171-0/+31
* Document firefox -- PLUGINSPAGE privileged javascript execution (alsosimon2005-04-171-0/+44
* Document jdk - jar directory traversal vulnerability.remko2005-04-171-0/+55
* Document several mozilla/firefox issues.simon2005-04-171-0/+303
* Mark wget >= 1.10.a1 safe from the "wget -- multiple vulnerabilities"simon2005-04-161-2/+5
* Document openoffice -- DOC document heap overflow vulnerability.simon2005-04-141-0/+74
* Fix and document insecure temporary file handling in portupgrade.simon2005-04-121-0/+51
* Document three GAIM vulnerabilities.simon2005-04-111-0/+103
* Document an old PHP issue.simon2005-04-111-0/+42
* Document squid -- DoS on failed PUT/POST requests vulnerability.simon2005-04-101-0/+28
* - Fix closing tag on the entry I just touched.pav2005-04-101-1/+1
* - Add <modified> to the entry I just touchedpav2005-04-101-0/+1
* - CAN-2005-0133 is fixed in clamav-devel-20050408pav2005-04-101-1/+1
* Bump modified date for entry modified last commit.simon2005-04-061-0/+1
* add CVE name to latest vuln of Cyrus IMAPd.ume2005-04-061-0/+1
* Add an entry for a XSS vulnerabilty fixed in horde-3.0.4.thierry2005-04-061-0/+38
* Document wu-ftpd -- remote globbing DoS vulnerability.simon2005-04-051-0/+40
* Add CVE name to hashash entry.simon2005-04-031-0/+2
* Document hashcash format string vulnerability.naddy2005-04-031-0/+29
* Document clamav -- zip handling DoS vulnerability.simon2005-03-271-0/+30
* Document Wine information disclosure.nectar2005-03-241-0/+43
* Document the most serious of the recently disclosednectar2005-03-241-0/+117
* Document Sylpheed buffer overflow.nectar2005-03-241-0/+31
* Document xv -- filename handling format string vulnerability.simon2005-03-221-0/+31
* Document kdelibs -- local DCOP denial of service vulnerability.simon2005-03-221-0/+37
* Mark grip port as fixed for recent vulnerability.simon2005-03-191-1/+2
* Document phpmyadmin -- increased privilege vulnerability.simon2005-03-161-0/+30
* Note that recent Quake2-LNX is fixed.danfe2005-03-161-1/+5
* Recent mysql snapshot import fixed several vulnerabilities.ale2005-03-151-5/+9
* Document ethereal -- multiple protocol dissectors vulnerabilities.simon2005-03-151-0/+46
* Document "grip -- CDDB response multiple matches buffer overflowsimon2005-03-151-0/+29
* Update references for latest MySQL entry:simon2005-03-151-1/+4
* Document multiple mysql remote vulnerabilities.ale2005-03-141-0/+43
* Add an entry about rxvt-unicode bufer overflow.thierry2005-03-131-0/+27
* Document two phpMyAdmin issues.simon2005-03-091-0/+82
* Document libexif -- buffer overflow vulnerability.simon2005-03-091-0/+27
* Fix invalid date.nectar2005-03-071-2/+2
* Add <modified> date for recent commit to phpbb vulnerability.nectar2005-03-071-2/+4
* Document a low risk HTML injection (configuration bypass)delphij2005-03-051-0/+31
* Add bugtraq bug ID for phpbb vulnerability.delphij2005-03-051-0/+1
* Document two phpnuke vulnerabilities, and a Linux RealPlayernectar2005-03-051-0/+109
* - Document ImageMagick -- format string vulnerability.simon2005-03-041-1/+33
* Document the privilege escalation vulnerability in uim.nobutaka2005-03-021-0/+33
* Fix typo in linux-tiff version number fornectar2005-03-011-2/+2
* Document lighttpd information disclosure bug.nectar2005-03-011-0/+33
* Fix typo in linux-tiff version number fornectar2005-02-281-1/+1
* Document latest phpBB critical security vulnerabilities.delphij2005-02-281-0/+31
* Correct the linux-tiff version number for several entries.nectar2005-02-281-8/+20
* Document curl -- authentication buffer overflow vulnerability.simon2005-02-281-0/+50
* - Document cyrus-imapd -- multiple buffer overflow vulnerabilities. [1]simon2005-02-281-1/+43
* Document format string vulnerabilities in net/sup.hrs2005-02-271-0/+33
* - Just use mozilla in title for last entry for consistency.simon2005-02-271-1/+77
* Update list of affected mozilla/firefox ports by the web browsers --simon2005-02-271-5/+14
* Document mozilla & firefox -- arbitrary code execution vulnerability.simon2005-02-261-0/+87
* Improve the description of the latest phpBB information disclosurenectar2005-02-251-5/+16
* Document a format string vulnerability in mkbold-mkitalic.hrs2005-02-241-0/+24
* Add CVE names for wget.nectar2005-02-241-0/+3
* De-confuse latest AWStats entry: rewrite description, and add relevantnectar2005-02-231-13/+22
* Format the <topic> of the most recent entry so that it is morenectar2005-02-231-1/+1
* Document latest phpbb vulnerabilities.delphij2005-02-231-0/+47
* Add more references to recent putty vulnerability.simon2005-02-231-0/+4
* The mod_dosevasive port was upgraded.nectar2005-02-231-1/+3
* Nit:nectar2005-02-231-26/+6
* Document unace-1.2b vulnerabilities: buffer overflows, directory traversal.naddy2005-02-221-0/+32
* For the the recent kdelibs entry; note that dcopidlng is only used atsimon2005-02-211-0/+4
* Document heap corruption vulnerabilities in putty.simon2005-02-211-0/+34
* Update affected versions of latest postgresql entry now that the portssimon2005-02-191-2/+4
* Document insecure temporary file creation in kdelibs.simon2005-02-191-0/+30
* Document format string vulnerability in bidwatcher.simon2005-02-191-0/+32
* Document a directory traversal vulnerability in gftp.simon2005-02-191-0/+33
* - Document two Opera vulnerabilities.simon2005-02-191-1/+73
* Document multiple buffer overflows in postgresql.simon2005-02-181-0/+31
* Fix entry date for last commit.simon2005-02-171-1/+1
* Document vulnerabilities in awstats. Note that this entry will mostsimon2005-02-171-0/+35
* Add a few more references to the awstats entry.simon2005-02-161-0/+3
* Change affected packages version for the emacs movemail format stringnobutaka2005-02-141-1/+1
* Document DoS in powerdns.simon2005-02-141-0/+26
* Document format string vulnerability in the Emacs movemail utility.simon2005-02-141-0/+53
* - Reflect fixing vulnerability in `net/opendchub'danfe2005-02-131-2/+3
* - Fix a cvename that should have been a certvu.simon2005-02-131-13/+16
* Document two vulnerabilities in ngircd.simon2005-02-131-0/+57
* Document mod_python information leakage vulnerability.simon2005-02-131-0/+32
* Document mailman directory traversal vulnerability.simon2005-02-131-0/+29
* Expand HTML entity reference in latest VuXML entry.nectar2005-02-121-1/+1
* Document enscript-{a4,letter,letterdj} vulnerabilities.naddy2005-02-121-0/+31
* Vulnerability in unrtf is fixed now.danfe2005-02-111-1/+2
* Document privilege escalation vulnerability in postgresql.simon2005-02-091-0/+38
* Document multiple protocol dissectors vulnerabilities in ethereal.simon2005-02-091-0/+53
* Add another squid issue.nectar2005-02-081-0/+34
* Add CERT Vulnerability Note reference for one squid issue,nectar2005-02-081-3/+4
* Add CVE name for squid confusing empty ACL issue.nectar2005-02-081-1/+2
* Add US-CERT Vulnerability Note references for recent squid issues.nectar2005-02-081-2/+5
* Add missing <code> markups in a citation from PSF-2005-001.perky2005-02-041-5/+5
* Add an entry for PSF-2005-001,perky2005-02-041-0/+52
* Update the entry for CAN-2005-0064 to indicate that gpdf 2.8.3 has a fixmarcus2005-02-041-2/+2
* Note that perl does not have a suidperl by default.nectar2005-02-031-0/+4
* Note vulnerabilities in perl.nectar2005-02-031-0/+33
* Add Bugtraq ID for evolution issue.nectar2005-02-021-0/+2
* Add CVE name for squid WCCP issue.nectar2005-02-021-0/+2
* Add a <modified> tag to the perl File::Path issue since the affectednectar2005-02-011-0/+1
* Narrow perl File::Path vulnerability version range a bit.tobez2005-02-011-1/+2
* Documented vulnerabilities found in the newspost, newsfetch and newsgrab ports.niels2005-02-011-0/+113
* The latest xpdf buffer overflow has been repaired in an updatenectar2005-02-011-2/+2
* Add CVE names for recent squid vulnerabilities.nectar2005-02-011-0/+6
* squid -- buffer overflow in WCCP recvfrom() callsem2005-01-301-0/+39
* Mark cups-base as fixed wrt. to "makeFileKey2() buffer overflowsimon2005-01-281-1/+2
* Document "makeFileKey2()" buffer overflow vulnerability in xpdf (andsimon2005-01-271-0/+60
* pdflib has been corrected.nectar2005-01-271-2/+2
* Document a vulnerability in zhcon.nectar2005-01-251-0/+31
* Fix last YAMT entry update to actually make sense... Greater than andsimon2005-01-251-1/+1
* Mark latest YAMT port version as fixed.simon2005-01-251-1/+2
* Document arbitrary code execution vulnerability in evolution.simon2005-01-251-0/+31
* Correct the entry date for 4e4bd2c2-6bd5-11d9-9e1e-c296ac722cb3nectar2005-01-251-1/+1
* Document a local vulnerability in mod_dosevasive.nectar2005-01-251-0/+36
* Document a possible cache-poisoning issue affecting squid.nectar2005-01-251-0/+42
* Document Bugzilla XSS issue.nectar2005-01-251-0/+35
* Oops, forgot to set <discovery> date.nectar2005-01-251-1/+1
* Document window injection vulnerabilities affecting several web browsers.nectar2005-01-251-2/+100
* Cancel duplicate phpbb entry e8c6ade2-6bcc-11d9-8e6f-000a95bc6fae. Itnectar2005-01-241-49/+32
* Document a vulnerability in YAMT.simon2005-01-241-0/+30
* Add squid security advisories for two recent squid entries.simon2005-01-221-2/+4
* squid bug #1200:edwin2005-01-221-0/+31
* Fix typo in last commit.simon2005-01-221-1/+1
* Document XSS in Horde.simon2005-01-221-0/+33
* Oops, I accidently changed an <entry> date when I should havenectar2005-01-221-1/+2
* Document vulnerabilities in older versions of Midnight Commander.nectar2005-01-221-0/+39
* Document a race condition in Perl's File::Path module.nectar2005-01-221-0/+26
* Document phpBB vulnerabilities.nectar2005-01-221-0/+41
* Document vulnerabilities in the Opera web browser's Java implementation.nectar2005-01-221-0/+56
* Document that older versions of sudo lack CDPATH environmental variablenectar2005-01-221-0/+27
* Document vulnerabilities in fcron.nectar2005-01-221-0/+35
* Document vulnerabilities in RealPlayer.nectar2005-01-221-0/+31
* Add CVE name and iDEFENSE advisory references to xzgv issue.nectar2005-01-211-1/+3
* Grr, get the imlib version number right!nectar2005-01-211-1/+1
* Oops, imlib 1.9.15 is still affected. Adjust version number to reflectnectar2005-01-211-1/+1
* Document xpm heap overflows and integer overflows affecting imlib and imlib2.nectar2005-01-211-0/+40
* Document a vulnerability in eGroupWare.nectar2005-01-211-0/+24
* Document Quake II vulnerabilities reported by Richard Stanway.nectar2005-01-211-0/+31
* Add CVE names for konversation bugs.nectar2005-01-211-0/+4
* Document security issue in irc/konversation.josef2005-01-201-0/+24
* Correct several instances where the "msgid" attribute content had annectar2005-01-201-4/+6
* Eliminate character entity references. They are technically fine ofnectar2005-01-201-1/+1
* Update entries with 12 new CVE name references.nectar2005-01-191-6/+25
* Fix date (was YYYY-MM-DD, now 2005-01-19)edwin2005-01-191-1/+1
* squid -- no sanity check of usernames in squid_ldap_authedwin2005-01-191-0/+37
* Document remote DoS in CUPS.simon2005-01-191-0/+25
* During last year's bumpercrop of vulnerabilities in libtiff, a 2004 CVEnectar2005-01-191-0/+34
* Document exploitable vulnerabilities in zgv and xzgv.nectar2005-01-191-0/+41
* Document bug in Mozilla-based software that may leave downloaded filesnectar2005-01-191-0/+78
* Add more references to exim entry.simon2005-01-191-1/+5
* pdflib contains libtiff, and thus is affected by several vulnerabilitiesnectar2005-01-181-3/+15
* Document remote command execution vulnerability in awstats.simon2005-01-181-0/+37
* Document security vulnerability in ImageMagick.simon2005-01-181-0/+36
* Update "cups-base -- HPGL buffer overflow vulnerability" entry tosimon2005-01-181-1/+1