Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_6 30 May 2025 18:05:05
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add chromium vulnerability
* CVE-2025-5063 |
1.1_6 30 May 2025 17:44:19
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-5268
* CVE-2025-5269
* CVE-2025-5270
* CVE-2025-5271
* CVE-2025-5272 |
1.1_6 30 May 2025 12:30:14
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mod_security DoS vulnerability
* CVE-2025-47947
PR: 278180 |
1.1_6 30 May 2025 02:42:16
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix entry 34744aab-3bf7-11f0-b81c-001b217e4ee5
Block-level elements such as <ul> are not allowed as children of <p>.
Fixes: 26d54384e9ef (security/vuxml: document kea vulnerabilities)
Sponsored by: The FreeBSD Foundation |
1.1_6 29 May 2025 22:46:18
    |
Thomas Zander (riggs)  |
security/vuxml: Document vulnerability in net/traefik |
1.1_6 29 May 2025 15:51:25
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add glpi vulnerabilities
* CVE-2024-11955
* CVE-2025-21619
* CVE-2025-21626
* CVE-2025-21627
* CVE-2025-23024
* CVE-2025-23046
* CVE-2025-24799
* CVE-2025-24801
* CVE-2025-25192 |
1.1_6 29 May 2025 15:08:48
    |
Brad Davis (brd)  |
security/vuxml: document kea vulnerabilities |
1.1_6 29 May 2025 05:36:05
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron{34,35} multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v34.5.7,
https://github.com/electron/electron/releases/tag/v35.5.0 |
1.1_6 28 May 2025 06:21:40
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Ammend entry for asterisk18
An extra 0 was in the version number.
Reported by: Sulev-Madis Silber |
1.1_6 27 May 2025 19:27:35
    |
Charlie Li (vishwin)  |
security/vuxml: adjust lang/python3 versions for CVE-2025-4516
PORTREVISIONs are bumped for each port containing the respective
upstream commit that is not included in any release yet.
PR: 287009 |
1.1_6 27 May 2025 15:58:22
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add grafana vulnerability
* CVE-2025-4123 |
1.1_6 24 May 2025 15:33:50
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add python3 vulnerability
* CVE-2025-4516
PR: 287009
Reported by: ngie@ |
1.1_6 23 May 2025 15:58:53
    |
Bernard Spil (brnrd)  |
security/vuxml: Document OpenSSL 3.5 vulnerability |
1.1_6 23 May 2025 12:28:26
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Firefox vulnerability
* CVE-2025-3608 |
1.1_6 23 May 2025 06:08:51
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 22 May 2025 18:51:40
    |
Brad Davis (brd)  |
security/vuxml: Document screen vulnerabilities |
1.1_6 19 May 2025 16:17:26
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox{-esr} vulnerabilities
* CVE-2025-4918
* CVE-2025-4919 |
1.1_6 17 May 2025 08:20:54
    |
Bernard Spil (brnrd)  |
security/vuxml: Document WeeChat vulnerabilities |
1.1_6 15 May 2025 08:29:57
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 136.0.7103.113
Obtained
from: https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html |
1.1_6 14 May 2025 15:28:05
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-4091
* CVE-2025-4093 |
1.1_6 14 May 2025 15:22:13
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix 2025.xml
Please, remember to always run "make validate" before committing.
fernape@ with ports-secteam@ hat on.
Fixes: 7e75a5ba66e3a |
1.1_6 14 May 2025 12:25:35
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document vscode security feature bypass vulnerability
Obtained
from: https://github.com/microsoft/vscode/security/advisories/GHSA-742r-ggwg-vqxm |
1.1_6 13 May 2025 22:30:00
    |
Charlie Li (vishwin)  |
security/vuxml: add textproc/libxslt
PR: 286782 |
1.1_6 12 May 2025 23:07:46
    |
Danilo G. Baio (dbaio)  |
security/vuxml: Add Varnish Cache vulnerability |
1.1_6 11 May 2025 16:48:21
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-4083
* CVE-2025-4085
* CVE-2025-4087
* CVE-2025-4088
* CVE-2025-4089
* CVE-2025-4092 |
1.1_6 10 May 2025 04:19:58
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 08 May 2025 20:00:15
    |
Palle Girgensohn (girgen)  |
security/vuxml: Add information about PostgreSQL overflow issue |
1.1_6 07 May 2025 06:40:58
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 136.0.7103.92
Obtained
from: https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop.html |
1.1_6 06 May 2025 06:37:48
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 136.0.7103.59
Obtained
from: https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.html |
1.1_6 05 May 2025 16:03:39
    |
Fernando Apesteguía (fernape)  Author: Christos Chatzaras |
security/vuxml: Add entry for fcgi < 2.4.5
PR: 286590
Reported by: chris@cretaforce.gr |
1.1_6 04 May 2025 16:08:21
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add dnsdist vulnerability
* CVE-2025-30194
PR: 286282 |
1.1_6 04 May 2025 03:04:21
    |
Philip Paeps (philip)  |
security/vuxml: libspf2 >= 1.2.11_1 not vulnerable
Fix the version range for libspf2 CVE-2023-42118.
libspf2 was patched in commit bbdef08a89c2124b0c149597f23d67c39cf3a522
to address CVE-2023-42118. PORTREVISION was bumped but vuxml was never
updated.
PR: 274215
Reported by: JC Burger <Jc.Burger@nttdata.com>
Security: CVE-2023-42118 |
1.1_6 01 May 2025 04:52:08
    |
Kurt Jaeger (pi)  Author: Ralf van der Enden |
security/vuxml: add VuXML entry for CVE-2025-30195 for dns/powerdns-recursor
PR: 286139
Reported-by: Jordan Ostreff <jordan@ostreff.info> |
1.1_6 01 May 2025 00:26:39
    |
Koichiro Iwao (meta)  Author: Tom Hukins |
security/vuxml: fix clumsy whitespace use
This text was added in 72eea8b with words split in half.
Pull Request: https://github.com/freebsd/freebsd-ports/pull/385 |
1.1_6 30 Apr 2025 17:18:21
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add sqlite vulnerability
* CVE-2025-29087 |
1.1_6 30 Apr 2025 12:58:58
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry range
PR: 286470
Reported by: Einar Bjarni Halldórsson <einar@isnic.is>
Fixes: 86c0781ad496e |
1.1_6 29 Apr 2025 19:55:55
    |
Kevin Bowling (kbowling)  |
security/vuxml: Fix navidrome range statement |
1.1_6 29 Apr 2025 13:10:08
    |
Muhammad Moinur Rahman (bofh)  |
net/py-h11: Update version 0.14.0=>0.16.0
- This addresses fix for CVE-2025-43859 — a critical vulnerability
affecting HTTP/1.1 connection handling.
- This update may break ports that depend on older h11 APIs, as some
interfaces and behaviors have changed in the new release.
Ports known or suspected to be affected should be tested carefully and
updated accordingly. A heads-up will also be sent to ports@.
Quarterly merge should take place after all the downstream ports have
been fixed for building.
Security: CVE-2025-43859
Changelog: https://github.com/python-hyper/h11/releases/tag/v0.16.0
MFH: 2025Q2 |
1.1_6 25 Apr 2025 06:25:12
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add grafana vulnerabilities
* CVE-2025-2703 - DOM XSS vulnerability (Medium)
* CVE-2025-3260 - Bypass Viewer and Editor permission (High)
* CVE-2025-3454 - Authorization bypass in data source proxy API (Medium)
PR: 286323
Reported by: Boris Korzun <drtr0jan@yandex.ru |
1.1_6 24 Apr 2025 08:20:30
    |
Yasuhiro Kimura (yasu)  |
security/vuxml: Document DoS vulnerability in redis and valkey |
1.1_6 24 Apr 2025 03:18:06
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 23 Apr 2025 04:49:55
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 135.0.7049.114
Obtained
from: https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_22.html |
1.1_6 22 Apr 2025 02:56:39
    |
Kevin Bowling (kbowling)  |
security/vuxml: Add multimedia/navidrome CVE-2025-27112 |
1.1_6 20 Apr 2025 17:59:50
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add lang/erlang* vulnerabilities
CVE-2025-32433
Reported by: Stefan Grundmann <sg@ennead.xyz> |
1.1_6 19 Apr 2025 09:08:51
    |
Ashish SHUKLA (ashish)  |
security/vuxml: Document ejabberd vulnerability |
1.1_6 16 Apr 2025 07:26:28
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 135.0.7049.95
Obtained
from: https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html |
1.1_6 15 Apr 2025 10:59:17
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add perl vulnerability
* CVE-2024-56406 |
1.1_6 15 Apr 2025 10:35:02
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Complete suricata entries
Add details for suricata vulnerabilities that were not disclosed at the time of
adding the entry.
Fixes: dedae0ab7185 |
1.1_6 15 Apr 2025 08:05:21
    |
Koichiro Iwao (meta)  Author: Tom Hukins |
security/vuxml: Fix spelling mistakes |
1.1_6 15 Apr 2025 07:40:28
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 135.0.7049.84
Obtained
from: https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_8.html |
1.1_6 15 Apr 2025 06:23:02
    |
Fernando Apesteguía (fernape)  |
security/vuxml: add gogs vulnerabilities
* CVE-2024-39930
* CVE-2024-39931
* CVE-2024-39932
* CVE-2024-39933
* CVE-2024-44625
PR: 280241 |
1.1_6 14 Apr 2025 08:08:35
    |
Ashish SHUKLA (ashish)  Author: Sascha Biberhofer |
security/vuxml: Document net-im/py-matrix-synapse vulnerability
PR: 285773 |
1.1_6 13 Apr 2025 16:57:28
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2024-11704
* CVE-2024-11706 |
1.1_6 11 Apr 2025 06:25:01
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2025-04-02
Sponsored by: The FreeBSD Foundation |
1.1_6 10 Apr 2025 04:24:09
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 09 Apr 2025 04:09:02
    |
Philip Paeps (philip)  |
security/vuxml: document CVE-2024-8176 (expat)
The textproc/expat2 port was already updated by diizzy@ on 25 March.
See commit a627ba49b6691cb8baf545c0d9b841458fb00859. |
1.1_6 07 Apr 2025 16:09:12
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-3028
* CVE-2025-3029
* CVE-2025-3030
* CVE-2025-3031
* CVE-2025-3032
* CVE-2025-3033
* CVE-2025-3034 |
1.1_6 05 Apr 2025 13:57:37
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 135.0.7049.52
Obtained
from: https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html |
1.1_6 04 Apr 2025 16:43:19
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Mozilla vulnerabilities
* CVE-2025-0237
* CVE-2025-0238
* CVE-2025-0239
* CVE-2025-0240
* CVE-2025-0241
* CVE-2025-0242
* CVE-2025-0243
* CVE-2025-0245
* CVE-2025-0247 |
1.1_6 04 Apr 2025 10:01:22
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add librewolf to recent vulns
Fixes: 5cf86187 14b335cd |
1.1_6 03 Apr 2025 16:04:10
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Mozilla multiple vulnerabilities
* CVE-2025-1931
* CVE-2025-1933
* CVE-2025-1934
* CVE-2025-1935
* CVE-2025-1937
* CVE-2025-1938
* CVE-2025-1943 |
1.1_6 03 Apr 2025 11:59:49
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb multiple vulnerabilities
* CVE-2022-3085
* CVE-2025-3083
* CVE-2025-3084 |
1.1_6 02 Apr 2025 19:22:24
    |
Matthias Andree (mandree)  |
security/vuxml: add openvpn<2.6.14 server DoS vuln
Security: 2cad4541-0f5b-11f0-89f8-411aefea0df9
Security: CVE-2025-2704 |
1.1_6 31 Mar 2025 16:40:30
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix firefox{-esr} version numbers
Fixes: 5f6d70f7ea52fb12b29ca098afa148441aa93df3 |
1.1_6 31 Mar 2025 16:37:07
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add gitea vulnerabilities
* CVE-2025-30204
* CVE-2025-29923
* CVE-2025-22870
PR: 285727 |
1.1_6 30 Mar 2025 17:08:19
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox derivative |
1.1_6 30 Mar 2025 16:51:16
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
Affects firefox, fireforx-esr, thunderbird
* CVE-2025-1942
* CVE-2025-1941
* CVE-2025-1932
* CVE-2025-27424 |
1.1_6 30 Mar 2025 12:25:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add suricata multiple vulnerabilities
No details have been published yet.
* CVE-2025-29915: HIGH
* CVE-2025-29916: Moderate
* CVE-2025-29917: HIGH
* CVE-2025-29918: HIGH
PR: 285574 |
1.1_6 29 Mar 2025 07:35:22
    |
Jason E. Hale (jhale)  |
security/vuxml: security/vuxml: Add www/qt6-webengine < 6.8.3
Also add print/qt6-pdf, since PDFium is involved this time. |
1.1_6 28 Mar 2025 12:01:07
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron{33,34} incorrect handle provided in
unspecified circumstances in Mojo
Obtained from: https://github.com/electron/electron/releases/tag/v33.4.8,
https://github.com/electron/electron/releases/tag/v34.4.1 |
1.1_6 26 Mar 2025 18:04:36
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 25 Mar 2025 12:14:46
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron{33,34} type confusion in V8
Obtained from: https://github.com/electron/electron/releases/tag/v33.4.6,
https://github.com/electron/electron/releases/tag/v34.3.4 |
1.1_6 23 Mar 2025 09:22:44
    |
Jason E. Hale (jhale)  |
security/vuxml: Add www/qt5-webengine < 5.15.18p7 |
1.1_6 22 Mar 2025 12:06:16
    |
Danilo G. Baio (dbaio)  |
security/vuxml: Add Varnish Cache vulnerability |
1.1_6 20 Mar 2025 07:50:33
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 134.0.6998.117
Obtained
from: https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_19.html |
1.1_6 14 Mar 2025 07:55:44
    |
Muhammad Moinur Rahman (bofh)  Author: Christos Chatzaras |
security/vuxml: Document PHP vulnerabilities
PR: 285386 |
1.1_6 13 Mar 2025 23:41:04
    |
Palle Girgensohn (girgen)  |
security/vuxml: Add security information about opensaml/shibboleth-sp |
1.1_6 13 Mar 2025 06:42:34
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 13 Mar 2025 05:02:24
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix 9cf03c96-ffa5-11ef-bb15-002590af0794 entry
vuxml build:
```
Application exception:
bad CVE name for vid 9cf03c96-ffa5-11ef-bb15-002590af0794: GHSA-693p-m996-3rmf
@ho:215
```
Fixes: 90289c6eaa01 vuxml: Document vim vulnerability
Sponsored by: The FreeBSD Foundation |
1.1_6 13 Mar 2025 01:00:48
    |
Adam Weinberger (adamw)  |
vuxml: Document vim vulnerability |
1.1_6 11 Mar 2025 08:49:31
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 134.0.6998.88
Obtained
from: https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_10.html |
1.1_6 10 Mar 2025 18:23:10
    |
Fernando Apesteguía (fernape)  |
security/vuxml: libreoffice macro URL arbitrary script execution |
1.1_6 10 Mar 2025 17:54:58
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add vim* shell commands execution |
1.1_6 08 Mar 2025 18:16:12
    |
Bryan Drewery (bdrewery)  |
security/vuxml: Update recent OpenSSH entry to include port |
1.1_6 08 Mar 2025 14:30:45
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron33 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v33.4.3 |
1.1_6 07 Mar 2025 19:44:34
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron32 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v32.3.3 |
1.1_6 06 Mar 2025 09:44:04
    |
Nicola Vitale (nivit)  |
security/vuxml: add devel/py-Jinja2 <= 3.1.5 |
1.1_6 06 Mar 2025 08:24:22
    |
Emmanuel Vadot (manu)  |
security/vuxml: Document recent xorg-server and xwayland vulnerabilities
Sponsored by: Beckhoff Automation GmbH & Co. KG |
1.1_6 06 Mar 2025 05:30:10
    |
Jose Alonso Cardenas Marquez (acm)  |
security/vuxml: Add security/caldera and security/caldera4 vulnerabilities
Obtained from: https://github.com/mitre/caldera/pull/3129 |
1.1_6 05 Mar 2025 19:42:46
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2025-03-05
Sponsored by: The FreeBSD Foundation |
1.1_6 05 Mar 2025 08:52:57
    |
Nicola Vitale (nivit)  |
security/vuxml: Add audio/py-spotify <= 2.24.0 |
1.1_6 05 Mar 2025 08:01:48
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 134.0.6998.35
Obtained
from: https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html |
1.1_6 04 Mar 2025 09:47:40
    |
Hiroki Tagato (tagattie)  |
security/vuxml: document electron{32,33} multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v32.3.2,
https://github.com/electron/electron/releases/tag/v33.4.2 |
1.1_6 03 Mar 2025 18:25:47
    |
Sergey A. Osokin (osa)  |
security/vuxml: document unit* vulnerabilities |
1.1_6 03 Mar 2025 12:49:53
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry
Add missing </p> tag.
Reported by: dan@langille.org
Fixes: 003195a3c754204bc61aaa39fea85fd62004b014 |
1.1_6 03 Mar 2025 04:45:48
    |
Adam Weinberger (adamw)  |
vuxml: Document vim code execution |
1.1_6 28 Feb 2025 04:20:04
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 27 Feb 2025 12:31:43
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 133.0.6943.141
Obtained
from: https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_25.html |
1.1_6 25 Feb 2025 13:04:58
    |
Joseph Mingrone (jrm)  |
security/vuxml: Update affected versions for recent Emacs entry
For entry e60e538f-e795-4a00-b475-cc85a7546e00, even though
CVE-2025-1244 was created recently, the workaround was committed to the
upstream master branch much earlier.
https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=820f0793f0b46448928905552726c1f1b999062f
After confirming details with an upstream developer, update the affected
editors/emacs-devel package versions.
Sponsored by: The FreeBSD Foundation |
1.1_6 25 Feb 2025 03:02:46
    |
Jason E. Hale (jhale)  |
security/vuxml: Add <= 0.28.0 exiv2 < 0.28.4
Add Med 5.3 CVE-2025-26623 for graphics/exiv2
https://github.com/Exiv2/exiv2/security/advisories/GHSA-38h4-fx85-qcx7 |