| Commit History - (may be incomplete: for full details, see links to repositories near top of page) | 
| Commit | Credits | Log message | 
1.1_6 03 Nov 2025 18:34:30
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add xorg-server, xwayland vulnerabilities
 * CVE-2025-62229
 * CVE-2025-62230
 * CVE-2025-62231  | 
1.1_6 03 Nov 2025 07:55:37
        | 
    Muhammad Moinur Rahman (bofh)   | 
    security/vuxml: Add entry for databases/redis  | 
1.1_6 02 Nov 2025 17:27:01
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Fix body tag indentation
To pass "make validate" without more modifications.  | 
1.1_6 02 Nov 2025 17:25:54
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Mozilla vulnerabilities
 * CVE-2025-9182
 * CVE-2025-9180
 * CVE-2025-11152
 * CVE-2025-10536
 * CVE-2025-10534
 * CVE-2025-10533
 * CVE-2025-10532
 * CVE-2025-10531
 * CVE-2025-10529
 * CVE-2025-10528
 * CVE-2025-10527  | 
1.1_6 01 Nov 2025 12:35:36
        | 
    Matthias Andree (mandree)   | 
    security/vuxml: mark Python 3.9 EOL
thus not receiving security support.  | 
1.1_6 31 Oct 2025 03:21:08
        | 
    Hiroki Tagato (tagattie)   Author: Ralf van der Enden | 
    security/vuxml: Document powerdns-recursor multiple vulnerabilities
PR:		290563
Reported by:	Ralf van der Enden <tremere@cainites.net>
Obtained
from:	https://blog.powerdns.com/powerdns-security-advisory-2025-06-2025-10-22  | 
1.1_6 30 Oct 2025 21:35:09
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 142.0.7444.59
Obtained
from:	https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html  | 
1.1_6 30 Oct 2025 17:04:07
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add firefox vulnerability
 * CVE-2025-12380  | 
1.1_6 30 Oct 2025 17:00:18
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Fix ranges for sqlite entries
Add PORTEPOCH  | 
1.1_6 30 Oct 2025 07:14:04
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Amend entries for sqlite3
Fix package name  | 
1.1_6 29 Oct 2025 21:48:34
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add erlan vulnerability
 * CVE-2025-4748
Reported by:	stephen.wall@redcom.com  | 
1.1_6 29 Oct 2025 19:52:09
        | 
    R. Christian McDonald (rcm)   | 
    security/vuxml: add kea vulnerability
* CVE-2025-11232
PR:		290660
Reviewed by:	brd
Sponsored by:	Rubicon Communications, LLC ("Netgate") | 
1.1_6 29 Oct 2025 16:16:05
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add SQLite vulnerability
 * CVE-2025-7709  | 
1.1_6 29 Oct 2025 15:02:48
        | 
    Kai Knoblich (kai)   | 
    security/vuxml: Document py-social-auth-app-django issue
* Do the same for for the Django 5.1 and 5.2 variants as well.
* CVE-2025-61783  | 
1.1_6 28 Oct 2025 22:44:54
        | 
    Dan Langille (dvl)   | 
    security/vuxml: Add privatebin CVE
Security:	https://www.cve.org/CVERecord?id=CVE-2025-62796  | 
1.1_6 28 Oct 2025 16:42:03
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Fix entry
Please, run "make validate" before commit.
Fixes:	a69ad955c4bd2  | 
1.1_6 28 Oct 2025 16:40:10
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add SQLite vulnerability
 * CVE-2025-52099  | 
1.1_6 28 Oct 2025 16:26:22
        | 
    Dan Langille (dvl)   | 
    security/vuxml: Add www/privatebin XSS issue
Security:	https://privatebin.info/reports/vulnerability-2025-10-28.html  | 
1.1_6 27 Oct 2025 18:58:23
        | 
    R. Christian McDonald (rcm)   | 
    security/vuxml: document eap-mschapv2 buffer overflow in strongSwan
* CVE-2025-62291
PR:		290578
Reviewed by:	brd
Sponsored by:	Rubicon Communications, LLC ("Netgate") | 
1.1_6 27 Oct 2025 14:27:48
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 141.0.7390.122
Obtained
from:	https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_21.html  | 
1.1_6 24 Oct 2025 15:47:49
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Improve newentry
Rearrange the code a bit by introducing providers.
Fields are retrieved from providers in an orderly fashion.
Should a provider fail to return a value, the next in the list is queried.
This should improve our chances of getting proper reports from different
providers.
Differential Revision:	https://reviews.freebsd.org/D52903  | 
1.1_6 23 Oct 2025 17:01:07
        | 
    R. Christian McDonald (rcm)   Author: Jaap Akkerhuis | 
    security/vuxml: document unbound non-DNSSEC cache poisoning vulns
* CVE-2025-11411
PR:		290429
Reviewed by:	brd
Sponsored by:	Rubicon Communications, LLC ("Netgate") | 
1.1_6 23 Oct 2025 15:33:05
        | 
    Fernando Apesteguía (fernape)   Author: Einar Bjarni Halldórsson | 
    security/vuxml: Add rt44, rt50 and rt60 vulnerabilities
 * CVE-2025-9158
 * CVE-2025-61873
PR:		290436
Report by:	Einar Bjarni Halldórsson <einar@isnic.is>  | 
1.1_6 23 Oct 2025 01:14:33
        | 
    Philip Paeps (philip)   | 
    security/vuxml: add FreeBSD SA issued on 2025-10-22
FreeBSD-SA-25:09.netinet affects all supported versions of FreeBSD.  | 
1.1_6 22 Oct 2025 16:18:13
        | 
    Matthias Fechner (mfechner)   | 
    security/vuxml: document gitlab vulnerabilities  | 
1.1_6 21 Oct 2025 16:57:56
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 141.0.7390.107
Obtained
from:	https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_14.html
Obtained
from:	https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop.html  | 
1.1_6 21 Oct 2025 13:45:49
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add mongodb[78] vulnerability
 * CVE-2025-11979  | 
1.1_6 20 Oct 2025 20:23:19
        | 
    Dan Langille (dvl)   | 
    security/vuxml: Add entry for net-mgmt/icingaweb2-module-icingadb
 * CVE-2025-61789  | 
1.1_6 19 Oct 2025 16:22:28
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add more Mozilla vulnerabilities
 * CVE-2025-11712
 * CVE-2025-11711
 * CVE-2025-11710
 * CVE-2025-11709
 * CVE-2025-11708
 * CVE-2025-11714
 While here improve another Mozilla entry description a bit.  | 
1.1_6 17 Oct 2025 17:55:04
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Mozilla vulnerabilities
 * CVE-2025-11715
 * CVE-2025-11721  | 
1.1_6 17 Oct 2025 17:25:00
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Firefox vulnerability
 * CVE-2025-11152  | 
1.1_6 17 Oct 2025 17:21:57
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Mozilla vulnerabilities
 * CVE-2025-10537
 * CVE-2025-10536
 * CVE-2025-10534
 * CVE-2025-10533  | 
1.1_6 17 Oct 2025 10:48:51
        | 
    Muhammad Moinur Rahman (bofh)   | 
    security/vuxml: Add report for minio  | 
1.1_6 13 Oct 2025 21:30:31
        | 
    Craig Leres (leres)   | 
    security/vuxml: Mark zeek < 8.0.2 as vulnerable as per:
    https://github.com/zeek/zeek/releases/tag/v8.0.2
This release fixes the following vulnerability:
 - The KRB analyzer can leak information about hosts in analyzed
   traffic via external DNS lookups.
Reported by:	Tim Wojtulewicz | 
1.1_6 13 Oct 2025 17:25:40
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Firefox vulnerability
 * CVE-2025-11153  | 
1.1_6 10 Oct 2025 08:51:17
        | 
    Matthias Fechner (mfechner)   | 
    security/vuxml: document gitlab vulnerabilities  | 
1.1_6 09 Oct 2025 11:13:39
        | 
    Guido Falsi (madpilot)   | 
    security/vuxml: Report mailpit information disclosure vuln
Obtained from:	https://github.com/axllent/mailpit/releases/tag/v1.27.10  | 
1.1_6 07 Oct 2025 15:50:01
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Mozilla vulnerabilities  | 
1.1_6 07 Oct 2025 06:21:45
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Fix mongodb entries
Remove entry that only affects 8.1.x which we don't still have in the repo.
Modify an entry removing the 8.1.x entry from the affected packages
Reported by:	ronald-lists@klop.ws
Fixes:		7ec6fda16269  | 
1.1_6 06 Oct 2025 16:34:20
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Mozilla vulnerabilities  | 
1.1_6 06 Oct 2025 15:50:56
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Remove redundant version information  | 
1.1_6 06 Oct 2025 15:43:39
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add mongodb vulnerabilities
 * CVE-2025-10061
 * CVE-2025-10060
 * CVE-2025-10059
 * CVE-2025-7259  | 
1.1_6 05 Oct 2025 17:27:00
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add mongodb6 vulnerability
 * CVE-2024-8654  | 
1.1_6 04 Oct 2025 12:00:53
        | 
    Muhammad Moinur Rahman (bofh)   | 
    security/vuxml: Add multiple CVEs for redis and valkey  | 
1.1_6 04 Oct 2025 09:34:35
        | 
    Matthias Andree (mandree)   | 
    security/vuxml: Add CVE-2025-61962 to fetchmail
add CVE-2025-61962 to existing fetchmail < 6.5.6 SMTP AUTH entry
Security:	21fba35e-a05f-11f0-a8b8-a1ef31191bc1
Security:	CVE-2025-61962  | 
1.1_6 04 Oct 2025 03:09:08
        | 
    Jason E. Hale (jhale)   | 
    security/vuxml: Add www/qt6-webengine < 6.9.3  | 
1.1_6 03 Oct 2025 13:58:16
        | 
    Matthias Andree (mandree)   | 
    security/vuxml: Add mail/fetchmail < 6.5.6 vuln (SMTP AUTH)
CVE requested from MITRE but not received yet.
URL:		https://www.fetchmail.info/fetchmail-SA-2025-01.txt
Security:	21fba35e-a05f-11f0-a8b8-a1ef31191bc1  | 
1.1_6 03 Oct 2025 07:13:30
        | 
    Philip Paeps (philip)   | 
    security/vuxml: reference FreeBSD-SA-25:08.openssl
Add a reference to FreeBSD-SA-25:08.openssl (issued 2025-09-30) to the
vuxml entry for OpenSSL CVE-2025-9230, CVE-2025-9231 and CVE-2025-9232.
FreeBSD-SA-25:08.openssl affects all supported versions of FreeBSD  | 
1.1_6 03 Oct 2025 07:03:05
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 141.0.7390.54
Obtained
from:	https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_30.html  | 
1.1_6 02 Oct 2025 23:17:17
        | 
    Wen Heping (wen)   | 
    security/vuxml: Document Django's multiple vulnerabilities  | 
1.1_6 01 Oct 2025 18:48:27
        | 
    Bernard Spil (brnrd)   | 
    security/vuxml: Mark OpenSSL 3.6 and 3.3 QUICTLS vulnerable too  | 
1.1_6 01 Oct 2025 09:44:24
        | 
    Muhammad Moinur Rahman (bofh)   | 
    security/vuxml: Add entry for py-mysql-connector-python
PR:		289934
Reported by:	patrik@hildingsson.se  | 
1.1_6 01 Oct 2025 06:52:15
        | 
    Bernard Spil (brnrd)   | 
    security/vuxml: Register OpenSSL vulnerabilities  | 
1.1_6 01 Oct 2025 06:43:48
        | 
    Bernard Spil (brnrd)   | 
    security/vuxml: Register LibreSSL vulnerability  | 
1.1_6 28 Sep 2025 16:16:39
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: krb5-1.20 is not vulnerable to CVE-2023-39975
PR:		274159
Reported by:	wollman@FreeBSD.org  | 
1.1_6 28 Sep 2025 16:03:03
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: fix SQLite entry
Vulnerable version range for sqlite currently bundled in
linux_base-rl9 (CVE-2025-6595).
PR:		289358
Reported by:	jcfyecrayz@liamekaens.com  | 
1.1_6 28 Sep 2025 15:55:04
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Record textproc/goldendict vulnerability  | 
1.1_6 26 Sep 2025 17:19:31
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Fix some reporters
Reported by:	dan@langille.org  | 
1.1_6 26 Sep 2025 16:17:33
        | 
    Fernando Apesteguía (fernape)   Author: Pau Amma | 
    security/vuxml: record security fixes in sysutils/libudisks 2.10.{2,91}
PR:		289689
Reported by:	pauamma@gundo.com | 
1.1_6 26 Sep 2025 15:59:40
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Fix entry
"SO-AND-SO" is not a valid reporter.
Fixes:	21c77e23be74b  | 
1.1_6 26 Sep 2025 15:57:23
        | 
    Florian Smeets (flo)   Author: Ralf van der Enden | 
    security/vuxml: Document net/quiche vulnerabilities
PR:		289810  | 
1.1_6 26 Sep 2025 15:30:04
        | 
    Florian Smeets (flo)   | 
    security/vuxml: Add 1.9.X branch of dnsdist to recent entry
PR:		289811  | 
1.1_6 26 Sep 2025 06:37:21
        | 
    Matthias Fechner (mfechner)   | 
    security/vuxml: gitlab vulnerabilities  | 
1.1_6 25 Sep 2025 23:34:48
        | 
    Matthias Andree (mandree)   | 
    security/vuxml: add openvpn-devel < 2.7beta2 vuln
PR:		289838
Security:	e5cf9f44-9a64-11f0-8241-93c889bb8de1
Security:	CVE-2025-10680  | 
1.1_6 24 Sep 2025 18:28:18
        | 
    Florian Smeets (flo)   Author: Ralf van der Enden | 
    security/vuxml: Add dns/dnsdist vulnerability < 2.0.1  | 
1.1_6 23 Sep 2025 21:00:20
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 140.0.7339.207
Obtained
from:	https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_23.html  | 
1.1_6 22 Sep 2025 12:31:03
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 140.0.7339.185
Obtained
from:	https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html  | 
1.1_6 20 Sep 2025 08:08:22
        | 
    Daniel Engberg (diizzy)   | 
    security/vuxml: Add pcre2 vulnerability
Document CVE-2025-58050  | 
1.1_6 18 Sep 2025 21:11:18
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: update expat records
Reported by:	delphij
Fixes:		f0e1c34246486f53b0636ec39f73edb116a52f3f  | 
1.1_6 18 Sep 2025 21:05:59
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: add expat2 vulnerability  | 
1.1_6 17 Sep 2025 18:38:44
        | 
    Li-Wen Hsu (lwhsu)   | 
    security/vuxml: Document Jenkins Security Advisory 2025-09-17
Sponsored by:	The FreeBSD Foundation  | 
1.1_6 16 Sep 2025 14:55:43
        | 
    Tijl Coosemans (tijl)   | 
    security/vuxml: Merge 2 entries for CUPS
Reported by:	osa  | 
1.1_6 16 Sep 2025 07:24:15
        | 
    Tijl Coosemans (tijl)   | 
    security/vuxml: Document CUPS vulnerabilities
CVE-2025-58060 cups: Authentication bypass with AuthType Negotiate
CVE-2025-58364 cups: Remote DoS via null dereference  | 
1.1_6 14 Sep 2025 18:29:31
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: correct the product version with a security fix  | 
1.1_6 14 Sep 2025 17:39:16
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: add www/unit-java vulnerability  | 
1.1_6 13 Sep 2025 21:59:21
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: update cups vulnerabilities  | 
1.1_6 12 Sep 2025 16:42:10
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: add print/cups < 2.4.13  | 
1.1_6 11 Sep 2025 08:27:28
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 140.0.7339.127
Obtained
from:	https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html  | 
1.1_6 11 Sep 2025 05:20:29
        | 
    Matthias Fechner (mfechner)   | 
    security/vuxml: document gitlab vulnerabilities  | 
1.1_6 07 Sep 2025 09:51:29
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 140.0.7339.80
Obtained
from:	https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.html  | 
1.1_6 05 Sep 2025 14:46:52
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: adjust libxslt version
Please visit https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289213
for details.  | 
1.1_6 04 Sep 2025 07:12:01
        | 
    Jason E. Hale (jhale)   | 
    security/vuxml: Add graphics/exiv2 < 0.28.6  | 
1.1_6 04 Sep 2025 02:47:26
        | 
    Wen Heping (wen)   | 
    security/vuxml: Document Django's multiple vulnerabilities  | 
1.1_6 03 Sep 2025 19:29:53
        | 
    Palle Girgensohn (girgen)   | 
    security/vuxml: document shibboleth vulnerability  | 
1.1_6 03 Sep 2025 15:38:54
        | 
    Nicola Vitale (nivit)   | 
    security/vuxml: Add www/linux-vieb < 12.4.0  | 
1.1_6 29 Aug 2025 03:22:52
        | 
    Matthias Fechner (mfechner)   | 
    security/vuxml: document gitlab vulnerabilities  | 
1.1_6 28 Aug 2025 19:42:05
        | 
    Renato Botelho (garga)   | 
    security/vuxml: Adjust affected kea versions
CVE-2025-40779 doesn't affect Kea 2.6.x, which is the version present on
quarterly branch.  On net/kea, it only affects 3.0.0 while it affects
3.1.0 and 2.7.x on net/kea-devel.  | 
1.1_6 28 Aug 2025 19:32:40
        | 
    Renato Botelho (garga)   Author: Andrey Pevnev | 
    security/vuxml: Add net/kea vulnerability
* CVE-2025-40779  | 
1.1_6 28 Aug 2025 05:06:27
        | 
    Jason E. Hale (jhale)   | 
    security/vuxml: Add devel/qt6-base < 6.9.2  | 
1.1_6 28 Aug 2025 05:06:26
        | 
    Jason E. Hale (jhale)   | 
    security/vuxml: Add www/qt6-webengine < 6.9.2  | 
1.1_6 27 Aug 2025 17:02:53
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Fix entry
Fixes:	35f7214f7a9ec  | 
1.1_6 27 Aug 2025 17:00:06
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add SQLite vulnerability
 * CVE-2025-29088  | 
1.1_6 24 Aug 2025 11:42:50
        | 
    Rodrigo Osorio (rodrigo)   | 
    security/vuxml: add p5-Catalyst-Authentication-Credential-HTTP  | 
1.1_6 22 Aug 2025 15:28:41
        | 
    Fernando Apesteguía (fernape)   | 
    security/vuxml: Add Mozilla vulnerabilities
 * CVE-2025-9187
 * CVE-2025-9184
 * CVE-2025-9185
 * CVE-2025-9183
 * CVE-2025-9182
 * CVE-2025-9181
 * CVE-2025-9180
 * CVE-2025-9179  | 
1.1_6 15 Aug 2025 16:10:38
        | 
    Sergey A. Osokin (osa)   | 
    security/vuxml: add www/nginx-devel < 1.29.1
Obtained from:	https://my.f5.com/manage/s/article/K000152786  | 
1.1_6 14 Aug 2025 19:16:40
        | 
    Robert Nagy (rnagy)   | 
    security/vuxml: add www/*chromium < 139.0.7258.127
Obtained
from:	https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html  | 
1.1_6 14 Aug 2025 14:10:16
        | 
    Palle Girgensohn (girgen)   | 
    security/vuxml: Add vulnerabilities for PostgreSQL  | 
1.1_6 14 Aug 2025 03:41:47
        | 
    Matthias Fechner (mfechner)   | 
    security/vuxml: document gitlab vulnerabilities  | 
1.1_6 13 Aug 2025 15:41:08
        | 
    Ryan Steinmetz (zi)   | 
    security/vuxml: Document www/varnish7 DoS condition  | 
1.1_6 13 Aug 2025 09:19:28
        | 
    Rodrigo Osorio (rodrigo)   | 
    security/vuxml: add security/p5-Authen-SASL  |