| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.1_6 19 Jan 2026 18:01:25
    |
Guido Falsi (madpilot)  |
security/vuxml: Document multiple mail/mailpit vulnerabilities |
1.1_6 19 Jan 2026 00:07:39
    |
Jesús Daniel Colmenares Oviedo (dtxdf)  |
security/vuxml: Add www/oauth2-proxy < 7.14.1 |
1.1_6 16 Jan 2026 17:49:53
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2026-0892
* CVE-2026-0889
* CVE-2026-0888
* CVE-2026-0881
* CVE-2026-0891
* CVE-2026-0890
* CVE-2026-0887
* CVE-2026-0885
* CVE-2026-0884
* CVE-2026-0883
* CVE-2026-0878
* CVE-2026-0886
* CVE-2026-0882
* CVE-2026-0880
* CVE-2026-0879
* CVE-2026-0877 |
1.1_6 15 Jan 2026 20:26:18
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 144.0.7559.59
Obtained
from: https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_13.html |
1.1_6 12 Jan 2026 13:52:48
    |
Nicola Vitale (nivit)  |
security/vuxml: Add devel/py-virtualenv <= 20.36.0 |
1.1_6 11 Jan 2026 15:33:05
    |
Roman Bogorodskiy (novel)  |
security/vuxml: document libtasn1 vulnerability
Security: CVE-2025-13151 |
1.1_6 11 Jan 2026 09:10:32
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulerabilities |
1.1_6 10 Jan 2026 18:18:01
    |
Guido Falsi (madpilot)  |
security/vuxml: security/vuxml: Document mail/mailpit vulnerability
(CVE-2026-22689) |
1.1_6 10 Jan 2026 12:58:28
    |
Florian Smeets (flo)  |
security/vuxml: Record phpmyfaq vulenrabilities |
1.1_6 07 Jan 2026 14:54:50
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.192
Obtained
from: https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop.html |
1.1_6 07 Jan 2026 10:21:50
    |
Vsevolod Stakhov (vsevolod)  |
security/vuxml: Document libsodium vuln CVE-2025-69277 |
1.1_6 06 Jan 2026 22:44:13
    |
Guido Falsi (madpilot)  |
security/vuxml: Document mail/mailpit vulnerability (CVE-2026-21859) |
1.1_6 06 Jan 2026 15:44:49
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document nets-snmp vuln (CVE-2025-68615) |
1.1_6 04 Jan 2026 07:27:57
    |
Jason E. Hale (jhale)  |
security/vuxml: Add gstreamer1-plugins-bad < 1.26.10
Update for 2026. |
1.1_6 04 Jan 2026 00:18:22
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Fix 613d0f9e-d477-11f0-9e85-03ddfea11990 syntax
PR: 291609
Fixes: 119cc45cd5f2 security/vuxml: update lang/python312 entry
Sponsored by: The FreeBSD Foundation |
1.1_6 03 Jan 2026 23:33:18
    |
Charlie Li (vishwin)  |
security/vuxml: update lang/python312 entry
PR: 291609 |
1.1_6 03 Jan 2026 22:47:51
    |
Matthias Andree (mandree)  |
security/vuxml: revise libxslt ~1.1.43 advisory of 2025
Security: b0a3466f-5efc-11f0-ae84-99047d0a6bcc |
1.1_6 02 Jan 2026 16:07:06
    |
Matthias Andree (mandree)  |
security/vuxml: update security entry for libxslt
PR: 289213 |
1.1_6 30 Dec 2025 20:39:04
    |
Kai Knoblich (kai)  |
security/vuxml: Adjust version range for py-pdfminer.six
* The fix for CVE-2025-64512 introduced with release 20251107 was
incomplete. This has been remedied with release 20251230, adjust
the entry accordingly. |
1.1_6 29 Dec 2025 16:47:24
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add forgejo vulnerability
* CVE-2025-68937 |
1.1_6 27 Dec 2025 18:55:34
    |
Ronald Klop (ronald)  |
security/vuxml: MongoBleed is also in 8.0.16 and before
Fixes: a69bda1
Fixes: b587cd0
Security: CVE-2025-14847 |
1.1_6 25 Dec 2025 11:07:26
    |
Thomas Zander (riggs)  |
security/vuxml: Document use-after-free in fluidsynth |
1.1_6 24 Dec 2025 18:23:18
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Amend entry for Mongodb
The port is for mongodb 8.0 and not 8.2
Reported by: ronald-lists@klop.ws |
1.1_6 22 Dec 2025 09:21:17
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb{78}0 vulnerability
* CVE-2025-14847 |
1.1_6 21 Dec 2025 12:27:27
    |
Thomas Zander (riggs)  |
security/vuxml: Document k8s / nginx cert validation bypass in traefik |
1.1_6 21 Dec 2025 12:23:03
    |
Thomas Zander (riggs)  |
security/vuxml: Document vuln via special characters in traefik |
1.1_6 20 Dec 2025 17:53:29
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add smb4k vulnerabilities
* CVE-2025-66002
* CVE-2025-66003 |
1.1_6 20 Dec 2025 16:51:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox vulnerabilities
* CVE-2025-14860
* CVE-2025-14861 |
1.1_6 19 Dec 2025 09:10:23
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.146
Obtained
from: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html |
1.1_6 18 Dec 2025 15:20:57
    |
Dan Langille (dvl)  |
security/vuxml: Correct the step-cli vuln
It's not the client, it's only the server: step-certificates |
1.1_6 17 Dec 2025 14:15:37
    |
Dan Langille (dvl)  |
security/vuxml: add security/step-cli vuln
re: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=291741
PR: 291741 |
1.1_6 17 Dec 2025 01:43:45
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SAs issued on 2025-12-17
FreeBSD-SA-25:11.ipfw affects FreeBSD 13.5 and FreeBSD 14.3
FreeBSD-SA-25:12.rtsold affects all supported versions of FreeBSD |
1.1_6 14 Dec 2025 09:42:11
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Roundcube vulnerabilitie |
1.1_6 13 Dec 2025 16:45:31
    |
Jesús Daniel Colmenares Oviedo (dtxdf)  |
security/vuxml: Add www/github-release-monitor < 1.4.1 |
1.1_6 12 Dec 2025 18:32:10
    |
Ryan Steinmetz (zi)  |
security/vuxml: Document vulnerability in www/varnish-libvmod-digest |
1.1_6 12 Dec 2025 16:21:41
    |
Li-Wen Hsu (lwhsu)  |
security/vuxml: Document Jenkins Security Advisory 2025-12-10
PR: 291580
Sponsored by: The FreeBSD Foundation |
1.1_6 12 Dec 2025 12:57:39
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add c-ares vulnerability
* CVE-2025-62408
PR: 291503
Reported by: polarian@polarian.dev |
1.1_6 12 Dec 2025 08:07:09
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.109
Obtained
from: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html |
1.1_6 11 Dec 2025 16:21:50
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mozilla, mongo vulnerabilities
* CVE-2025-14345
* CVE-2025-14333
* CVE-2025-14332
* CVE-2025-14331
* CVE-2025-14330
* CVE-2025-14329
* CVE-2025-14328
* CVE-2025-14327
* CVE-2025-14326
* CVE-2025-14325
* CVE-2025-14324
* CVE-2025-14323
* CVE-2025-14322
* CVE-2025-14321 |
1.1_6 11 Dec 2025 04:06:38
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 08 Dec 2025 21:15:42
    |
Matthias Andree (mandree)  |
security/vuxml: version Python vuln entries
Security: 613d0f9e-d477-11f0-9e85-03ddfea11990
Security: CVE-2025-12084
Security: CVE-2025-13836 |
1.1_6 08 Dec 2025 21:01:11
    |
Matthias Andree (mandree)  |
security/vuxml: add Python <3.13.11/<3.14.2 vulns
Security: 613d0f9e-d477-11f0-9e85-03ddfea11990
Security: CVE-2025-12084
Security: CVE-2025-13836 |
1.1_6 06 Dec 2025 10:05:30
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 143.0.7499.40
Obtained
from: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop.html |
1.1_6 06 Dec 2025 08:31:43
    |
Nicola Vitale (nivit)  |
security/vuxml: Add audio/py-spotipy <= 2.25.1 |
1.1_6 05 Dec 2025 19:09:52
    |
Fernando Apesteguía (fernape)  Author: Polarian |
security/vuxml: Add xkbcomp vulnerabilities
* CVE-2018-15853
* CVE-2018-15859
* CVE-2018-15861
* CVE-2018-15863
PR: 291407
Reported by: Polarian <polarian@polarian.dev> |
1.1_6 05 Dec 2025 06:14:17
    |
Charlie Li (vishwin)  Author: Polarian |
security/vuxml: Out of bounds read in graphics/png
PR: 291266, 291410 |
1.1_6 04 Dec 2025 19:26:59
    |
Roman Bogorodskiy (novel)  |
security/vuxml: add entry for libvirt vulnerabilities
* CVE-2025-12748
* CVE-2025-13193 |
1.1_6 04 Dec 2025 17:46:49
    |
Bernard Spil (brnrd)  |
security/vuxml: Document Apache httpd vulnerabilities |
1.1_6 04 Dec 2025 16:18:57
    |
Fernando Apesteguía (fernape)  Author: Einar Bjarni Halldórsson |
security/vuxml: Add entry for go124, go125
* CVE-2025-61729
PR: 291366
Reported by: einar@isnic.is |
1.1_6 01 Dec 2025 16:56:30
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb multiple vulnerabilities
* CVE-2025-13644
* CVE-2025-13507
* CVE-2025-13643 |
1.1_6 30 Nov 2025 21:57:25
    |
Santhosh Raju (fox)  |
security/vuxml: Document wolfSSL multiple vulnerabilities. |
1.1_6 29 Nov 2025 16:53:19
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb{7,8}0 vulnerability
* CVE-2025-12893 |
1.1_6 28 Nov 2025 00:03:25
    |
Philip Paeps (philip)  |
security/vuxml: reference FreeBSD-SA-25:10.unbound
Add a reference to FreeBSD-SA-25:10.unbound (issued 2025-11-26) to the
vuxml entry for Unbound CVE-2025-11411.
FreeBSD-SA-25:10.unbound affects all supported versions of FreeBSD |
1.1_6 27 Nov 2025 16:43:55
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add png vulnerabilities
* CVE-2025-65018
* CVE-2025-64720
* CVE-2025-64506
* CVE-2025-64505
Reported by: Stefan Grundmann <sg2342@googlemail.com> |
1.1_6 27 Nov 2025 04:19:30
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 21 Nov 2025 11:06:42
    |
Tijl Coosemans (tijl)  |
security/vuxml: Add GNUTLS-SA-2025-11-18 |
1.1_6 18 Nov 2025 10:05:51
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 142.0.7444.175
Obtained
from: https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html |
1.1_6 17 Nov 2025 22:42:15
    |
Matthias Andree (mandree)  |
security/vuxml: add pkcs11-helper < 1.31.0 parser buffer overflow |
1.1_6 17 Nov 2025 22:08:55
    |
Matthias Andree (mandree)  |
security/vuxml: add two OpenVPN CVEs
Security: 50a0c266-c3ff-11f0-b513-0da7be77c170
Security: CVE-2025-12106
Security: 17a40d76-c3fd-11f0-b513-0da7be77c170
Security: CVE-2025-13086 |
1.1_6 17 Nov 2025 07:25:03
    |
Kai Knoblich (kai)  |
security/vuxml: Document py-pdfminer.six security issue
* CVE-2025-64512 - 8.6 |
1.1_6 17 Nov 2025 00:57:07
    |
Koichiro Iwao (meta)  |
security/vuxml: Document sudo-rs < 0.2.10 vulnerabilites
PR: 290945 |
1.1_6 14 Nov 2025 16:48:54
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add postgresql{13,14,15,16,17,18}-client vulnerabilities
* CVE-2025-12818 - 5.9
* CVE-2025-12817 - 3.1 |
1.1_6 13 Nov 2025 18:20:28
    |
Max Brazhnikov (makc)  |
security/vuxml: lightdm-kde-greeter vulnerability |
1.1_6 13 Nov 2025 18:12:16
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Mozilla multiple vulnerabilities
* CVE-2025-13012 - 7.5
* CVE-2025-13013 - 6.1
* CVE-2025-13014 - 6.1
* CVE-2025-13015 - 3.4
* CVE-2025-13016 - 7.5
* CVE-2025-13017 - 6.1
* CVE-2025-13018 - 6.1
* CVE-2025-13019 - 6.1
* CVE-2025-13020 - 6.1
* CVE-2025-13021 - 7.5
* CVE-2025-13022 - 7.5
* CVE-2025-13023 - 7.5
* CVE-2025-13024 - 7.5
* CVE-2025-13025 - 7.5
* CVE-2025-13026 - 7.5
* CVE-2025-13027 - 7.5 |
1.1_6 13 Nov 2025 16:57:09
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix newentry template |
1.1_6 13 Nov 2025 12:38:19
    |
Matthias Fechner (mfechner)  |
security/vuxml: correct syntax
Reported by: dan@langille.org |
1.1_6 13 Nov 2025 04:45:13
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |
1.1_6 12 Nov 2025 12:31:40
    |
Dan Langille (dvl)  |
security/vuxml: add www/privatebin vuln CVE-2025-62796 |
1.1_6 12 Nov 2025 08:09:59
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 142.0.7444.162
Obtained
from: https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_11.html |
1.1_6 07 Nov 2025 17:11:52
    |
Matthias Andree (mandree)  |
security/vuxml: Revise SQLite3 entry
- mention this bug is only for >= 3.49.1 according to
https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g
- advance the discovery date to Mid July per the same
- strip double -9.6 from linux_base-rl9 name to get the entry to
actually trigger for the package, and set it to ">= 0" because
we don't want unrelated updates to linux_base-rl9-9.6 make this
entry disappear. It's left for emulation@ to clean up.
Security: CVE-2025-7709
Security: c5889223-b4e1-11f0-ae9b-b42e991fc52e |
1.1_6 07 Nov 2025 07:11:38
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 142.0.7444.134
Obtained
from: https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html |
1.1_6 05 Nov 2025 22:52:55
    |
Matthias Andree (mandree)  |
security/vuxml: document openjph < 0.24.5 vulnerabilites
Security: 77bac392-ba98-11f0-aada-f59a8ea34d12 |
1.1_6 05 Nov 2025 22:52:55
    |
Matthias Andree (mandree)  |
security/vuxml: OpenEXR < 3.4.3 multiple vulnerabilities
Security: c71a3914-ba96-11f0-aada-f59a8ea34d12 |
1.1_6 05 Nov 2025 16:06:58
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add mongodb70 vulnerability
* CVE-2025-12657 |
1.1_6 04 Nov 2025 07:07:23
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry
Add PORTEPOCH
Fixes: 73e65844 |
1.1_6 03 Nov 2025 18:34:30
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add xorg-server, xwayland vulnerabilities
* CVE-2025-62229
* CVE-2025-62230
* CVE-2025-62231 |
1.1_6 03 Nov 2025 07:55:37
    |
Muhammad Moinur Rahman (bofh)  |
security/vuxml: Add entry for databases/redis |
1.1_6 02 Nov 2025 17:27:01
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix body tag indentation
To pass "make validate" without more modifications. |
1.1_6 02 Nov 2025 17:25:54
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add Mozilla vulnerabilities
* CVE-2025-9182
* CVE-2025-9180
* CVE-2025-11152
* CVE-2025-10536
* CVE-2025-10534
* CVE-2025-10533
* CVE-2025-10532
* CVE-2025-10531
* CVE-2025-10529
* CVE-2025-10528
* CVE-2025-10527 |
1.1_6 01 Nov 2025 12:35:36
    |
Matthias Andree (mandree)  |
security/vuxml: mark Python 3.9 EOL
thus not receiving security support. |
1.1_6 31 Oct 2025 03:21:08
    |
Hiroki Tagato (tagattie)  Author: Ralf van der Enden |
security/vuxml: Document powerdns-recursor multiple vulnerabilities
PR: 290563
Reported by: Ralf van der Enden <tremere@cainites.net>
Obtained
from: https://blog.powerdns.com/powerdns-security-advisory-2025-06-2025-10-22 |
1.1_6 30 Oct 2025 21:35:09
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 142.0.7444.59
Obtained
from: https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html |
1.1_6 30 Oct 2025 17:04:07
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add firefox vulnerability
* CVE-2025-12380 |
1.1_6 30 Oct 2025 17:00:18
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix ranges for sqlite entries
Add PORTEPOCH |
1.1_6 30 Oct 2025 07:14:04
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Amend entries for sqlite3
Fix package name |
1.1_6 29 Oct 2025 21:48:34
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add erlan vulnerability
* CVE-2025-4748
Reported by: stephen.wall@redcom.com |
1.1_6 29 Oct 2025 19:52:09
    |
R. Christian McDonald (rcm)  |
security/vuxml: add kea vulnerability
* CVE-2025-11232
PR: 290660
Reviewed by: brd
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 29 Oct 2025 16:16:05
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add SQLite vulnerability
* CVE-2025-7709 |
1.1_6 29 Oct 2025 15:02:48
    |
Kai Knoblich (kai)  |
security/vuxml: Document py-social-auth-app-django issue
* Do the same for for the Django 5.1 and 5.2 variants as well.
* CVE-2025-61783 |
1.1_6 28 Oct 2025 22:44:54
    |
Dan Langille (dvl)  |
security/vuxml: Add privatebin CVE
Security: https://www.cve.org/CVERecord?id=CVE-2025-62796 |
1.1_6 28 Oct 2025 16:42:03
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Fix entry
Please, run "make validate" before commit.
Fixes: a69ad955c4bd2 |
1.1_6 28 Oct 2025 16:40:10
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Add SQLite vulnerability
* CVE-2025-52099 |
1.1_6 28 Oct 2025 16:26:22
    |
Dan Langille (dvl)  |
security/vuxml: Add www/privatebin XSS issue
Security: https://privatebin.info/reports/vulnerability-2025-10-28.html |
1.1_6 27 Oct 2025 18:58:23
    |
R. Christian McDonald (rcm)  |
security/vuxml: document eap-mschapv2 buffer overflow in strongSwan
* CVE-2025-62291
PR: 290578
Reviewed by: brd
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 27 Oct 2025 14:27:48
    |
Robert Nagy (rnagy)  |
security/vuxml: add www/*chromium < 141.0.7390.122
Obtained
from: https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_21.html |
1.1_6 24 Oct 2025 15:47:49
    |
Fernando Apesteguía (fernape)  |
security/vuxml: Improve newentry
Rearrange the code a bit by introducing providers.
Fields are retrieved from providers in an orderly fashion.
Should a provider fail to return a value, the next in the list is queried.
This should improve our chances of getting proper reports from different
providers.
Differential Revision: https://reviews.freebsd.org/D52903 |
1.1_6 23 Oct 2025 17:01:07
    |
R. Christian McDonald (rcm)  Author: Jaap Akkerhuis |
security/vuxml: document unbound non-DNSSEC cache poisoning vulns
* CVE-2025-11411
PR: 290429
Reviewed by: brd
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 23 Oct 2025 15:33:05
    |
Fernando Apesteguía (fernape)  Author: Einar Bjarni Halldórsson |
security/vuxml: Add rt44, rt50 and rt60 vulnerabilities
* CVE-2025-9158
* CVE-2025-61873
PR: 290436
Report by: Einar Bjarni Halldórsson <einar@isnic.is> |
1.1_6 23 Oct 2025 01:14:33
    |
Philip Paeps (philip)  |
security/vuxml: add FreeBSD SA issued on 2025-10-22
FreeBSD-SA-25:09.netinet affects all supported versions of FreeBSD. |
1.1_6 22 Oct 2025 16:18:13
    |
Matthias Fechner (mfechner)  |
security/vuxml: document gitlab vulnerabilities |