Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
1.1_6 01 Feb 2025 08:23:08 |
Yasuhiro Kimura (yasu) |
security/vuxml: Update entries for redis and valkey
Add affected range for redis-devel package. |
1.1_6 31 Jan 2025 07:37:55 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 132.0.6834.159
Obtained
from: https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_28.html |
1.1_6 30 Jan 2025 20:26:36 |
Michael Reifenberger (mr) |
security/vaultwarden: Security update to 1.33.0
Also added CVE IDs to security/vuxml vaulwarden entry.
PR: 284399
Reported by: foudfou |
1.1_6 30 Jan 2025 16:28:03 |
Ashish SHUKLA (ashish) |
security/vuxml: Document net-im/dendrite vulneraability |
1.1_6 30 Jan 2025 04:02:20 |
Philip Paeps (philip) |
security/vuxml: add FreeBSD SAs issued on 2025-01-29
FreeBSD-SA-25:01.openssh affects FreeBSD 14.1
FreeBSD-SA-25:02.fs affects all supported versions of FreeBSD
FreeBSD-SA-25:03.etcupdate affects all supported versions of FreeBSD
FreeBSD-SA-25:04.ktrace affects FreeBSD 14.2 |
1.1_6 30 Jan 2025 04:02:19 |
Philip Paeps (philip) |
security/vuxml: fix whitespace errors in recent oauth2-proxy entry
Turn some spaces into tabs to make `make validate` happy. The errors
were introduced in ab5f837462e075723c1be8573d178751b2ba2ede earlier
today.
Pointy hat to: rm |
1.1_6 29 Jan 2025 21:06:04 |
Ruslan Makhmatkhanov (rm) |
security/vuxml: add www/oauth2-proxy < 7.8.0 entry
PR: 284059
Reported by: Matthias Wolf <freebsd@rheinwolf.de> |
1.1_6 25 Jan 2025 14:23:09 |
Bernard Spil (brnrd) |
security/vaultwarden: Register <= 1.32.7 vulns |
1.1_6 25 Jan 2025 08:12:01 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 132.0.6834.110
Obtained
from: https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_22.html
Obtained
from: https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_14.html |
1.1_6 25 Jan 2025 05:46:22 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron32 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v32.3.0 |
1.1_6 23 Jan 2025 14:26:04 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron33 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v33.3.2 |
1.1_6 23 Jan 2025 07:34:49 |
Matthias Fechner (mfechner) |
security/vuxml: document gitlab vulnerabilities |
1.1_6 23 Jan 2025 03:40:39 |
Yasuhiro Kimura (yasu) |
security/vuxml: Document possbile denial-of-service vulnerability in clamav |
1.1_6 22 Jan 2025 13:22:18 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron32 type confusion in v8 vulnerability
Obtained from: https://github.com/electron/electron/releases/tag/v32.2.8 |
1.1_6 21 Jan 2025 22:21:09 |
Ashish SHUKLA (ashish) |
security/vuxml: Document lang/go* vulnerabilities
PR: 284181 |
1.1_6 20 Jan 2025 13:39:38 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron31 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v31.7.7 |
1.1_6 18 Jan 2025 08:05:02 |
Xin LI (delphij) |
security/vuxml: Document age arbitrary binary execution vulnerability. |
1.1_6 17 Jan 2025 01:40:05 |
Matthias Andree (mandree) |
security/vuxml: mention security/openvpn username/password length bugfix of
v2.6.13
I am not aware of a CVE number yet.
Security: 47bc292a-d472-11ef-aaab-7d43732cb6f5 |
1.1_6 15 Jan 2025 13:54:44 |
Li-Wen Hsu (lwhsu) |
security/vuxml: Fix entry 163edccf-d2ba-11ef-b10e-589cfc10a551
Fixes: e39886d24184 security/vuxml: add net/rsync vulnerabilities
Sponsored by: The FreeBSD Foundation |
1.1_6 14 Jan 2025 21:27:45 |
Sergey A. Osokin (osa) |
security/vuxml: add net/rsync vulnerabilities |
1.1_6 14 Jan 2025 21:07:45 |
Joseph Mingrone (jrm) |
security/vuxml: Update 2025-01-13 keycloak entry to fix `make validate`
Reported by: garga
Sponsored by: The FreeBSD Foundation |
1.1_6 14 Jan 2025 20:49:16 |
Renato Botelho (garga) |
security/vuxml: Add devel/git vulnerabilities
Sponsored by: Rubicon Communications, LLC ("Netgate") |
1.1_6 14 Jan 2025 16:11:09 |
Vladimir Druzenko (vvd) Author: Matthias Wolf |
security/vuxml: Add record for net/keycloak
CVE-2024-11736 Unrestricted admin use of system and environment variables
CVE-2024-11734 Denial of Service in Keycloak Server via Security Headers
Security: CVE-2024-11734
Security: CVE-2024-11736
PR: 284058 |
1.1_6 12 Jan 2025 19:04:57 |
Fernando Apesteguía (fernape) |
security/vuxml: add asterisk{18,20} vulns
CVE-2024-53566: Path traversal
* Base Score: 5.5 MEDIUM
* Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
1.1_6 10 Jan 2025 05:23:35 |
Yasuhiro Kimura (yasu) |
security/vuxml: Document two valnerabilities in redis and valkey
While here, update copyright year |
1.1_6 08 Jan 2025 19:07:47 |
Matthias Fechner (mfechner) |
security/vuxml: document gitlab vulnerabilities |
1.1_6 06 Jan 2025 16:54:50 |
Fernando Apesteguía (fernape) |
security/vuxml: Fix sqlite range
PR: 283830
Reported by: John Hein <jcfyecrayz@liamekaens.com> |
1.1_6 31 Dec 2024 16:41:37 |
Cy Schubert (cy) |
security/vuxml: Update open-motif entry to reflect fix in 2004
Release notes states:
2.2.4 October 2004
a. Fixed vulnerabilities in libXpm code [CVE numbers CAN-2004-0687
(integer overflows) and CAN-2004-0688 (stack overflows)]. |
1.1_6 31 Dec 2024 16:20:32 |
Cy Schubert (cy) |
security/vuxml: Note Xpm update in open-motif-devel
Upstream open-motif updated built-in Xpm to 3.5.12 in upstream commit
b100c321 making it no longer vulnerable. |
1.1_6 29 Dec 2024 13:22:03 |
Fernando Apesteguía (fernape) |
security/vuxml: TOCTOU Vulnerability in www/apache*
CVE-2024-56337 |
1.1_6 24 Dec 2024 11:25:23 |
Fernando Apesteguía (fernape) |
security/vuxml: www/kanboard vulnerability
Insufficient session validation. |
1.1_6 20 Dec 2024 14:14:19 |
Bernard Spil (brnrd) |
security/vuxml: Document Vaultwarden vulnerability |
1.1_6 19 Dec 2024 12:10:35 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 131.0.6778.204
Obtained
from: https://chromereleases.googleblog.com/2024/12/stable-channel-update-for-desktop_18.html |
1.1_6 18 Dec 2024 19:00:44 |
Bernard Spil (brnrd) |
security/vuxml: Document liboqs vulnerability |
1.1_6 18 Dec 2024 05:47:43 |
Philip Paeps (philip) |
security/vuxml: fix parse errors
Fix parse errors introduced in 96ddbb42b98fcb6022729ea28cd6725fcfdc4597. |
1.1_6 18 Dec 2024 00:04:58 |
Vladimir Druzenko (vvd) Author: Stefan Bethke |
security/vuxml: add records for www/gitea < 1.22.6
https://github.com/go-gitea/gitea/pull/32810
https://github.com/advisories/GHSA-v778-237x-gjrc
https://github.com/go-gitea/gitea/pull/32791
https://github.com/go-gitea/gitea/pull/32654
https://github.com/go-gitea/gitea/pull/32531
https://github.com/go-gitea/gitea/pull/32473
PR: 283389 |
1.1_6 17 Dec 2024 23:52:04 |
Vladimir Druzenko (vvd) Author: Stefan Bethke |
security/vuxml: add records for www/forgejo < 9.0.3 and www/forgejo7 < 7.0.12
https://codeberg.org/forgejo/forgejo/pulls/5974
https://codeberg.org/forgejo/forgejo/pulls/6248
https://codeberg.org/forgejo/forgejo/pulls/6249
PR: 283388 |
1.1_6 16 Dec 2024 22:13:39 |
Ashish SHUKLA (ashish) |
security/vuxml: Document net-im/py-matrix-synapse vulnerability
Signed-off-by: Sascha Biberhofer <sascha.biberhofer@skyforge.at>
PR: 283350
Reviewed by: ashish |
1.1_6 16 Dec 2024 19:20:40 |
Fernando Apesteguía (fernape) Author: John Hein |
security/vuxml: Fix range for thunderbird vulnerability
PR: 283357
Reported by: John Hein <jcfyecrayz@liamekaens.com> |
1.1_6 16 Dec 2024 19:15:22 |
Craig Leres (leres) |
security/vuxml: Mark zeek < 7.0.5 as vulnerable as per:
https://github.com/zeek/zeek/releases/tag/v7.0.5
This release fixes the following potential DoS vulnerability:
- Large QUIC packets can cause Zeek to overflow memory and potentially
crash. Due to the possibility of receiving these packets from
remote hosts, this is a DoS risk.
Reported by: Tim Wojtulewicz |
1.1_6 15 Dec 2024 11:36:17 |
Yuri Victorovich (yuri) Author: Älven |
textproc/halibut: update 1.2 → 1.3
PR: 282213 |
1.1_6 12 Dec 2024 05:39:59 |
Matthias Fechner (mfechner) |
security/vuxml: document gitlab vulnerabilities |
1.1_6 11 Dec 2024 14:07:36 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 131.0.6778.139
Obtained
from: https://chromereleases.googleblog.com/2024/12/stable-channel-update-for-desktop_10.html
Obtained
from: https://chromereleases.googleblog.com/2024/12/stable-channel-update-for-desktop.html |
1.1_6 10 Dec 2024 19:10:23 |
Fernando Apesteguía (fernape) |
security/vuxml: Add mozilla vulnerabilities
* CVE-2024-11692
* CVE-2024-11696
* CVE-2024-11697
* CVE-2024-11699 |
1.1_6 07 Dec 2024 15:59:31 |
Jason E. Hale (jhale) |
security/vuxml: Add www/qt6-webengine < 6.7.3_3 |
1.1_6 06 Dec 2024 16:56:56 |
Jason E. Hale (jhale) |
security/vuxml: Document gstreamer1-plugins* < 1.24.10 |
1.1_6 02 Dec 2024 20:04:55 |
Fernando Apesteguía (fernape) |
security/vuxml: Add zabbix-frontend vulnerability
* Base Score: 9.9 CRITICAL
* Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
1.1_6 02 Dec 2024 19:40:36 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron33 inappropriate implementation in extensions
Obtained from: https://github.com/electron/electron/releases/tag/v33.2.1 |
1.1_6 29 Nov 2024 03:15:03 |
Li-Wen Hsu (lwhsu) |
security/vuxml: security/vuxml: Document Jenkins Security Advisory 2024-11-27
Sponsored by: The FreeBSD Foundation |
1.1_6 27 Nov 2024 11:57:29 |
Robert Clausecker (fuz) Author: Matthias Wolf |
net/keycloak: document multiple vulnerabilities
Security: CVE-2024-9666 CVE-2024-10039 CVE-2024-10270
Security: CVE-2024-10451 CVE-2024-10492
PR: 282983 |
1.1_6 27 Nov 2024 05:39:27 |
Matthias Fechner (mfechner) |
security/vuxml: document gitlab vulnerabilities |
1.1_6 25 Nov 2024 08:48:30 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 131.0.6778.85
Obtained
from: https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_19.html |
1.1_6 23 Nov 2024 15:57:43 |
Jason E. Hale (jhale) |
security/vuxml: Add www/qt6-webengine < 6.7.3_2 |
1.1_6 23 Nov 2024 05:40:00 |
Jason E. Hale (jhale) |
security/vuxml: Add www/qt5-webengine < 5.15.18p5 |
1.1_6 19 Nov 2024 18:57:57 |
Kurt Jaeger (pi) |
security/vuxml: Add x11-servers/xorg-server, x11-servers/xwayland
PR: 282415 |
1.1_6 19 Nov 2024 16:28:53 |
Michael Reifenberger (mr) |
security/vuxml: Add vaultwarden
Vaultwarden -- Multiple vulnerabilities
PR: 282795
Reported by: Bernard Spil |
1.1_6 18 Nov 2024 16:16:23 |
Fernando Apesteguía (fernape) |
security/vuxml: Add mongodb vulnerability
Buffer over-read. |
1.1_6 16 Nov 2024 12:22:32 |
Bernard Spil (brnrd) |
security/vuxml: Document vaultwarden vulnerabilities |
1.1_6 16 Nov 2024 08:14:28 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron32 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v32.2.5 |
1.1_6 16 Nov 2024 07:34:26 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 131.0.6778.69
Obtained
from: https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop_12.html |
1.1_6 15 Nov 2024 17:28:01 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron31 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v31.7.5 |
1.1_6 14 Nov 2024 16:29:07 |
Palle Girgensohn (girgen) |
security/vuxml: Add CVEs for PostreSQL |
1.1_6 14 Nov 2024 09:22:31 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron31 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v31.7.4 |
1.1_6 14 Nov 2024 05:03:07 |
Matthias Fechner (mfechner) |
security/vuxml: document gitlab vulnerabilities |
1.1_6 13 Nov 2024 04:21:13 |
Philip Paeps (philip) |
security/vuxml: add FreeBSD SAs issued on 2024-10-29
FreeBSD-SA-24:17.bhyve affects all supported versions of FreeBSD
FreeBSD-SA-24:18.ctl affects all supported versions of FreeBSD
FreeBSD-SA-24:19.fetch affects all supported versions of FreeBSD |
1.1_6 12 Nov 2024 22:20:17 |
Ashish SHUKLA (ashish) |
security/vuxml: Document element-web vulnerabilities
Security: CVE-2024-51749
Security: CVE-2024-51750 |
1.1_6 12 Nov 2024 22:20:16 |
Ashish SHUKLA (ashish) |
security/vuxml: Document matrix-js-sdk vulnerability
Security: CVE-2024-50336 |
1.1_6 12 Nov 2024 20:41:13 |
Florian Smeets (flo) |
security/vuxml: Document icinga2 vulnerability |
1.1_6 12 Nov 2024 19:50:39 |
Joseph Mingrone (jrm) |
security/vuxml: Document new Intel CPU vulnerabilities
Intel has disclosed new CPU vulnerabilities in the release notes for
microcode-20241112. This release also includes updates to previous
microcode updates for CVE-2024-24968 and CVE-2024-23984.
Reference: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20241112
Security: CVE-2024-21820
Security: CVE-2024-21853
Security: CVE-2024-23918
Security: CVE-2024-23984 (updated microcode)
Security: CVE-2024-24968 (updated microcode)
Sponsored by: The FreeBSD Foundation |
1.1_6 08 Nov 2024 17:49:55 |
Dirk Meyer (dinoex) |
security/vuxml: add CVE-2018-10195, CVE-2020-29074 |
1.1_6 08 Nov 2024 14:04:20 |
Renato Botelho (garga) Author: Älven |
security/vuxml: Document tnef vulnerabilities
PR: 282228 |
1.1_6 08 Nov 2024 11:24:02 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron32 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v32.2.3 |
1.1_6 08 Nov 2024 01:22:51 |
Jason E. Hale (jhale) |
security/vuxml: Document gstreamer1-rtsp-server
Only affected if assertions are enabled, which we don't do by default. |
1.1_6 06 Nov 2024 12:03:21 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 130.0.6723.116
Obtained
from: https://chromereleases.googleblog.com/2024/11/stable-channel-update-for-desktop.html |
1.1_6 04 Nov 2024 19:01:32 |
Vladimir Druzenko (vvd) Author: Älven |
security/vuxml: Add record for devel/libqb < 2.0.8 CVE-2023-39976
log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long
log messages because the header size is not considered.
https://nvd.nist.gov/vuln/detail/CVE-2023-39976
PR: 282536 |
1.1_6 02 Nov 2024 08:14:11 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 130.0.6723.91
Obtained
from: https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_29.html |
1.1_6 01 Nov 2024 00:41:09 |
Jason E. Hale (jhale) |
security/vuxml: Add www/qt5-webengine < 5.15.18p2
Fix indentation issues caught by `make validate` for previous entry. |
1.1_6 31 Oct 2024 10:50:31 |
Vladimir Druzenko (vvd) Author: Matthias Wolf |
security/vuxml: Add record for net/keycloak < 26.0.4 CVE-2021-44549
PR: 282419 |
1.1_6 30 Oct 2024 18:47:01 |
Vladimir Druzenko (vvd) Author: Martin Filla |
security/vuxml: www/librewolf < 131.0.3 CVE-2024-9936
PR: 282423 |
1.1_6 29 Oct 2024 15:37:50 |
Vladimir Druzenko (vvd) Author: Älven |
security/vuxml: Add record for devel/hwloc2 < 2.9.2 CVE-2022-47022
PR: 282215 |
1.1_6 29 Oct 2024 15:24:02 |
Vladimir Druzenko (vvd) Author: Stefan Bethke |
security/vuxml: add record for www/forgejo < 9.0.1 and www/forgejo7 < 7.0.10
https://codeberg.org/forgejo/forgejo/milestone/8544
https://codeberg.org/forgejo/forgejo/pulls/5719
https://codeberg.org/forgejo/forgejo/pulls/5718
PR: 282387 |
1.1_6 26 Oct 2024 13:12:25 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 130.0.6723.{58,69}
Obtained
from: https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_22.html
Obtained from:
https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_15.html |
1.1_6 24 Oct 2024 11:51:36 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron31 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v31.7.2 |
1.1_6 24 Oct 2024 04:45:07 |
Matthias Fechner (mfechner) |
security/vuxml: document gitlab vulnerabilities |
1.1_6 23 Oct 2024 20:33:44 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron32 multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v32.2.2 |
1.1_6 21 Oct 2024 09:36:03 |
Robert Clausecker (fuz) |
security/vuxml: document www/oauth2-proxy vulnerabilities
Reported by: Matthias Wolf <freebsd@rheinwolf.de>
PR: 282004 |
1.1_6 19 Oct 2024 15:52:43 |
Bernard Spil (brnrd) |
security/vuxml: OpenSSL 3.4 not affected by CVE-2024-9143 |
1.1_6 19 Oct 2024 15:06:24 |
Bernard Spil (brnrd) |
security/vuxml: Fix and add OpenSSL versions |
1.1_6 19 Oct 2024 14:57:57 |
Bernard Spil (brnrd) |
security/vuxml: Document OpenSSL low vulnerability |
1.1_6 18 Oct 2024 08:35:16 |
Hiroki Tagato (tagattie) |
security/vuxml: document electron{31,32} multiple vulnerabilities
Obtained from: https://github.com/electron/electron/releases/tag/v31.7.1,
https://github.com/electron/electron/releases/tag/v32.2.1 |
1.1_6 15 Oct 2024 15:03:24 |
Ashish SHUKLA (ashish) |
security/vuxml: Document element-web vulnerability |
1.1_6 11 Oct 2024 08:13:00 |
Hiroki Tagato (tagattie) |
security/vuxml: document VSCode remote code execution vulnerability
Obtained from: https://github.com/microsoft/vscode/issues/230824 |
1.1_6 10 Oct 2024 17:59:22 |
Fernando Apesteguía (fernape) |
security/vuxml: Fix typo in firefox entry
Reported by: jbeich@ |
1.1_6 10 Oct 2024 17:33:23 |
Fernando Apesteguía (fernape) |
security/vuxml: Add firefox{-esr} use-after-free code execution
CVE-2024-9680 |
1.1_6 10 Oct 2024 02:46:53 |
Matthias Fechner (mfechner) |
security/vuxml: document gitlab vulnerabilities |
1.1_6 09 Oct 2024 22:08:03 |
Vladimir Druzenko (vvd) Author: Stefan Bethke |
security/vuxml: Add record for www/gitea: Fix bug when a token is given public
only
PR: 281949 |
1.1_6 09 Oct 2024 20:26:44 |
Vladimir Druzenko (vvd) Author: Ralf van der Enden |
security/vuxml: Add record about CVE-2024-25590 in dns/powerdns-recursor
PowerDNS Recursor Security Advisory 2024-04:
https://blog.powerdns.com/2024/10/03/powerdns-recursor-4-9-9-5-0-9-5-1-2-released
PR: 281914 |
1.1_6 09 Oct 2024 17:46:50 |
Robert Nagy (rnagy) |
security/vuxml: add www/*chromium < 129.0.6668.{89,100}
Obtained
from: https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop.html
Obtained
from: https://chromereleases.googleblog.com/2024/10/stable-channel-update-for-desktop_8.html |
1.1_6 09 Oct 2024 15:35:07 |
Fernando Apesteguía (fernape) |
security/vuxml: Fix Thunderbird version
PR: 281960
Reported by: John Hein <jcfyecrayz@liamekaens.com>
Fixes: 86d1aa3caa24c97cdc63962d13fef16be12c84b7 |
1.1_6 06 Oct 2024 16:16:19 |
Robert Clausecker (fuz) |
security/vuxml: document unbound vulnerability
PR: 281894
Security: CVE-2024-8508
Security: 2368755b-83f6-11ef-8d2e-a04a5edf46d9 |