This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2024-12-02 20:06:50 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
---|---|
111f1f84-1d14-4ff2-a9ea-cf07119c0d3b | libyaml heap overflow resulting in possible code execution libyaml was prone to a heap overflow that could result in arbitrary code execution. Pkg uses libyaml to parse the package manifests in some cases. Pkg also used libyaml to parse the remote repository until 1.2. RedHat Product Security Team reports on libyaml:
Discovery 2013-11-24 Entry 2014-02-01 Modified 2014-02-01 libyaml < 0.1.4_3 pkg < 1.2.6 pkg-devel < 1.2.6 CVE-2013-6393 https://bugzilla.redhat.com/show_bug.cgi?id=1033990 |
2af10639-4299-11ea-aab1-98fa9bfec35a | pkg -- vulnerability in libfetch A programming error allows an attacker who can specify a URL with a username and/or password components to overflow libfetch(3) buffers. Discovery 2020-01-28 Entry 2020-01-29 pkg < 1.12.0_1 pkg-devel < 1.12.99_1 SA-20:01.libfetch CVE-2020-7450 |