FreeBSD VuXML

Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Security issues that affect the FreeBSD operating system or applications in the FreeBSD Ports Collection are documented using the Vulnerabilities and Exposures Markup Language (VuXML). The current VuXML document that serves as the source for the content of this site can be found:

Please report security issues to the FreeBSD Security Team at . Full contact details, including information handling policies and PGP key, can be found on the FreeBSD Security page.

VuXML ID index


VuXML ID Topic
00263aa3-67a8-11d8-80e3-0020ed76ef5a mailman XSS in user options page
00644f03-fb58-11d8-9837-000c41e2cdad imlib -- BMP decoder heap buffer overflow
00784d6e-f4ce-11da-87a1-000c6ec775d9 squirrelmail -- plugin.php local file inclusion vulnerability
01356ccc-6a87-11da-b96e-000fb586ba73 horde -- Cross site scripting vulnerabilities in several of Horde's templates
013fa252-0724-11d9-b45d-000c41e2cdad mod_dav -- lock related denial-of-service
0163b498-af54-11d9-acd0-000854d03344 axel -- remote buffer overflow
01bb84e2-bd88-11d9-a281-02e018374e71 groff -- pic2graph and eqn2graph are vulnerable to symlink attack through temporary files
01c231cd-4393-11d9-8bb9-00065be4b5b6 mysql -- GRANT access restriction problem
02274fd9-6bc5-11d9-8edb-000a95bc6fae realplayer -- arbitrary file deletion and other vulnerabilities
022baf71-38e6-11dd-8d34-00e0815b8da8 Courier Authentication Library -- SQL Injection
024edd06-c933-11dc-810c-0016179b2dd5 xfce -- multiple vulnerabilities
027380b7-3404-11d9-ac1b-000d614f7fad hafiye -- lack of terminal escape sequence filtering
0274a9f1-0759-11da-bc08-0001020eed82 postnuke -- multiple vulnerabilities
02bc9b7c-e019-11d9-a8bd-000cf18bbe54 acroread -- XML External Entity vulnerability
02eedd3c-c6b5-11dc-93b6-000e35248ad7 libxine -- buffer overflow vulnerability
035d17b2-484a-11d9-813c-00065be4b5b6 mysql -- erroneous access restrictions applied to table renames
03653079-8594-11d9-afa0-003048705d5a phpbb -- multiple information disclosure vulnerabilities
045944a0-6bca-11d9-aaa6-000a95bc6fae sudo -- environmental variable CDPATH is not cleared
04c6187d-2d8f-11dd-98c9-00163e000016 linux-flashplugin -- unspecified remote code execution vulnerability
0512b761-70fb-40d3-9954-aa4565528fa8 kstars -- exploitable set-user-ID application fliccd
05dcf751-0733-11d9-b45d-000c41e2cdad cups -- print queue browser denial-of-service
063399fc-f6d6-11dc-bcee-001c2514716c bzip2 -- crash with certain malformed archive files
06404241-b306-11d9-a788-0001020eed82 kdelibs -- kimgio input validation errors
064225c5-1f53-11d9-836a-0090962cff2a squid -- NTLM authentication denial-of-service vulnerability
0679deeb-8eaf-11db-abc9-0003476f14d3 sql-ledger -- multiple vulnerabilities
06a6b2cf-484b-11d9-813c-00065be4b5b6 mysql -- ALTER MERGE denial of service vulnerability
06f142ff-4df3-11d9-a9e7-0001020eed82 wget -- multiple vulnerabilities
072a53e0-0397-11dd-bd06-0017319806e7 postfix-policyd-weight -- working directory symlink vulnerability
077c2dca-8f9a-11db-ab33-000e0c2e438a openssl -- Incorrect PKCS#1 v1.5 padding validation in crypto(3)
0792e7a7-8e37-11d8-90d1-0020ed76ef5a CVS path validation errors
07ead557-a220-11da-b410-000e0c2e438a WebCalendar -- unauthorized access vulnerability
07f3fe15-a9de-11d9-a788-0001020eed82 php -- readfile() DoS vulnerability
0832ee18-cf77-11dc-8c6a-00304881ac9a jetty -- multiple vulnerability
0838733d-1698-11dc-a197-0011098b2f36 wordpress -- XMLRPC SQL Injection
08ac7b8b-bb30-11da-b2fb-000e0c2e438a sendmail -- race condition vulnerability
08df5d46-1baf-11da-8038-0040f42d58c6 urban -- stack overflow vulnerabilities
09066828-2ef1-11dd-a0d8-0016d325a0ed ikiwiki -- empty password security hole
09429f7c-fd6e-11da-b1cd-0050bf27ba24 horde -- multiple parameter cross site scripting vulnerabilities
09639ccc-3abb-11db-81e1-000e0c2e438a hlstats -- multiple cross site scripting vulnerabilities
09c92f3a-fd49-11da-995c-605724cdf281 webcalendar -- information disclosure vulnerability
09d418db-70fd-11d8-873f-0020ed76ef5a Apache 1.3 IP address access control failure on some 64-bit platforms
09db2844-0b21-11da-bc08-0001020eed82 gaim -- AIM/ICQ non-UTF-8 filename crash
0ab423e7-3822-11db-81e1-000e0c2e438a joomla -- multiple vulnerabilities
0ac1aace-f7b9-11da-9156-000e0c2e438a ypserv -- Inoperative access controls in ypserv
0ac89b39-f829-11db-b55c-000e0c6d38a9 qemu - several vulnerabilities
0b2b4b4d-a07c-11da-be0a-000c6ec775d9 postgresql81-server -- SET ROLE privilege escalation
0b628470-e9a6-11da-b9f4-00123ffe8333 coppermine -- Multiple File Extensions Vulnerability
0b79743b-3ab7-11db-81e1-000e0c2e438a gtetrinet -- remote code execution
0bb7677d-52f3-11d9-a9e7-0001020eed82 krb5 -- heap buffer overflow vulnerability in libkadm5srv
0bf9d7fb-05b3-11da-bc08-0001020eed82 mambo -- multiple vulnerabilities
0c0dc409-1c5e-11da-92ce-0048543d60ce squid -- Possible Denial Of Service Vulnerability in store.c
0c4d5973-f2ab-11d8-9837-000c41e2cdad mysql -- mysqlhotcopy insecure temporary file creation
0c592c4a-1bcc-11d9-a3ec-00061bd2d56f cyrus-sasl -- potential buffer overflow in DIGEST-MD5 plugin
0c6f3fde-9c51-11d8-9366-0020ed76ef5a Midnight Commander buffer overflows, format string bugs, and insecure temporary file handling
0cf3480d-5fdf-11d9-b721-00065be4b5b6 helvis -- arbitrary file deletion problem
0d3a5148-f512-11d8-9837-000c41e2cdad SpamAssassin -- denial-of-service in tokenize_headers
0d4c31ac-cb91-11d8-8898-000d6111a684 Remote code injection in phpMyAdmin
0d9ba03b-0dbb-42b4-ae0f-60e27af78e22 sympa -- buffer overflow in "queue"
0e154a9c-5d7a-11d8-80e3-0020ed76ef5a seti@home remotely exploitable buffer overflow
0e43a14d-3f3f-11dc-a79a-0016179b2dd5 xpdf -- stack based buffer overflow
0e575ed3-0764-11dc-a80b-0016179b2dd5 squirrelmail -- Cross site scripting in HTML filter
0f37d765-c5d4-11db-9f82-000e0c2e438a OpenSSL -- Multiple problems in crypto(3)
0f5a2b4d-694b-11d9-a9e7-0001020eed82 awstats -- remote command execution vulnerability
0ff0e9a6-4ee0-11d9-a9e7-0001020eed82 phpmyadmin -- command execution vulnerability
1033750f-cab4-11d9-9aed-000e0c2e438a oops -- format string vulnerability
104beb63-af4d-11da-8414-0013d4a4a40e mplayer -- heap overflow in the ASF demuxer
107692a1-ee6c-11d9-8310-0001020eed82 acroread -- insecure temporary file creation
107e2ee5-f941-11da-b1fa-020039488e34 libxine -- buffer overflow vulnerability
114d70f3-3d16-11d9-8818-008088034841 Cyrus IMAPd -- PARTIAL command out of bounds memory corruption
116b0820-d59c-11da-8098-00123ffe8333 lifetype -- ADOdb "server.php" Insecure Test Script Security Issue
11a84092-8f9f-11db-ab33-000e0c2e438a gzip -- multiple vulnerabilities
12488805-6773-11dc-8be8-02e0185f8d72 coppermine -- multiple vulnerabilities
12b1a62d-6056-4d90-9e21-45fcde6abae4 gallery -- remote code injection via HTTP_POST_VARS
12b336c6-fe36-11dc-b09c-001c2514716c mozilla -- multiple vulnerabilities
12b7286f-16a2-11dc-b803-0016179b2dd5 webmin -- cross site scripting vulnerability
12b7b4cf-1d53-11d9-814e-0001020eed82 wordpress -- XSS in administration panel
12bd6ecf-c430-11db-95c5-000c6ec775d9 mozilla -- multiple vulnerabilities
12c7b7ae-ec90-11d8-b913-000c41e2cdad popfile file disclosure
12d266b6-363f-11dc-b6c9-000c6ec775d9 opera -- multiple vulnerabilities
12f9d9e9-9e1e-11da-b410-000e0c2e438a phpicalendar -- cross site scripting vulnerability
131bd7c4-64a3-11d9-829a-000a95bc6fae libxine -- DVD subpicture decoder heap overflow
1374b96c-a1c2-11db-9ddc-0011098b2f36 sircd -- remote reverse DNS buffer overflow
142353df-b5cc-11d9-a788-0001020eed82 gaim -- remote DoS on receiving malformed HTML
1489df94-6bcb-11d9-a21e-000a95bc6fae opera -- multiple vulnerabilities in Java implementation
14ad2a28-66d2-11dc-b25f-02e0185f8d72 konquerer -- address bar spoofing
15485ae8-9848-11dc-9e48-0016179b2dd5 phpmyadmin -- Cross Site Scripting
15e0e963-02ed-11d9-a209-00061bc2ad93 mpg123 buffer overflow
15ec9123-7061-11dc-b372-001921ab2fa4 id3lib -- insecure temporary file creation
1613db79-8e52-11da-8426-000fea0a9611 kpopup -- local root exploit and local denial of service
168190df-3e9a-11dd-87bc-000ea69a5213 fetchmail -- potential crash in -v -v verbose mode
169f422f-bd88-11d9-a281-02e018374e71 groff -- groffer uses temporary files unsafely
1709084d-4d21-11db-b48d-00508d6a62df plans -- multiple vulnerabilities
172acf78-780c-11dc-b3f4-0016179b2dd5 png -- multiple vulnerabilities
17f53c1d-2ae9-11db-a6e2-000e0c2e438a postgresql -- encoding based SQL injection
180e9a38-060f-4c16-a6b7-49f3505ff22a kernel -- information disclosure when using HTT
184ab9e0-64cd-11d9-9e1e-c296ac722cb3 squid -- buffer overflow vulnerability in gopherToHTML
184f5d0b-0fe8-11d9-8a8a-000c41e2cdad subversion -- WebDAV fails to protect metadata
18974c8a-1fbd-11d9-814e-0001020eed82 apache13-modssl -- format string vulnerability in proxy support
18a14baa-5ee5-11db-ae08-0008743bf21a ingo -- local arbitrary shell command execution
18e3a5be-81f9-11db-95a2-0012f06707f0 ImageMagick -- SGI Image File heap overflow vulnerability
18e5428f-ae7c-11d9-837d-000e0c2e438a jdk -- jar directory traversal vulnerability
19207592-5f17-11db-ae08-0008743bf21a drupal -- HTML attribute injection
19518d22-2d05-11d9-8943-0050fc56d258 putty -- buffer overflow vulnerability in ssh2 support
197f444f-e8ef-11d9-b875-0001020eed82 bzip2 -- denial of service and permission race vulnerabilities
1986449a-8b74-40fa-b7cc-0d8def8aad65 openvpn -- denial of service: malicious authenticated "tap" client can deplete server virtual memory
1989b511-ae62-11d9-a788-0001020eed82 mozilla -- code execution through javascript: favicons
19a92df1-548d-11db-8f1a-000a48049292 tin -- buffer overflow vulnerabilities
19b17ab4-51e0-11db-a5ae-00508d6a62df phpmyadmin -- XSRF vulnerabilities
1a216dfd-f710-11da-9156-000e0c2e438a freeradius -- authentication bypass vulnerability
1a32e8ee-3edb-11d9-8699-00065be4b5b6 ProZilla -- server response buffer overflow vulnerabilities
1a448eb7-6988-11d8-873f-0020ed76ef5a mod_python denial-of-service vulnerability in parse_qs
1a818749-d646-11dc-8959-000bcdc1757a zenphoto -- XSS vulnerability
1ac77649-0908-11dd-974d-000fea2763ce lighttpd -- OpenSSL Error Queue Denial of Service Vulnerability
1b043693-8617-11db-93b2-000e35248ad7 libxine -- multiple buffer overflow vulnerabilities
1b70bef4-649f-11d9-a30e-000a95bc6fae libxine -- multiple buffer overflows in RTSP
1b725079-9ef6-11da-b410-000e0c2e438a sudo -- arbitrary command execution
1c0def84-5fb1-11db-b2e9-0008c79fa3d2 asterisk -- remote heap overwrite vulnerability
1c3142a3-4ab2-11da-932d-00055d790c25 squid -- FTP server response handling denial of service
1cf00643-ed8a-11d9-8310-0001020eed82 cacti -- multiple vulnerabilities
1d3a2737-7eb7-11d9-acf7-000854d03344 unace -- multiple vulnerabilities
1daea60a-4719-11da-b5c6-0004614cc33d ruby -- vulnerability in the safe level settings
1db1ed59-af07-11d8-acb9-000d610a3b12 buffer cache invalidation implementation issues
1db7ecf5-fd24-11d9-b4d6-0007e900f87b clamav -- multiple remote buffer overflows
1e606080-3293-11da-ac91-020039488e34 uim -- privilege escalation vulnerability
1e6c4008-245f-11d9-b584-0050fc56d258 gaim -- buffer overflow in MSN protocol support
1e8e63c0-478a-11dd-a88d-000ea69a5213 fetchmail -- potential crash in -v -v verbose mode (revised patch)
1ecf4ca1-f7ad-11d8-96c9-00061bc2ad93 moinmoin -- ACL group bypass
1ed03222-3c65-11dc-b3d3-0016179b2dd5 vim -- Command Format String Vulnerability
1f2fdcff-ae60-11d9-a788-0001020eed82 firefox -- arbitrary code execution in sidebar panel
1f5b711b-3d0e-11dc-b3d3-0016179b2dd5 drupal -- Multiple cross-site scripting vulnerabilities
1f6e2ade-35c2-11da-811d-0050bf27ba24 imap-uw -- mailbox name handling remote buffer vulnerability
1f738bda-c6ac-11d8-8898-000d6111a684 Remote Denial of Service of HTTP server and client
1f826757-26be-11d9-ad2d-0050fc56d258 rssh -- format string vulnerability
1f922de0-3fe5-11d9-a9e7-0001020eed82 unarj -- directory traversal vulnerability
1f935f61-075d-11db-822b-728b50d539a3 Joomla -- multiple vulnerabilities
1fa4c9f1-cfca-11da-a672-000e0c2e438a FreeBSD -- FPU information disclosure
1fe734bf-4a06-11db-b48d-00508d6a62df opera -- RSA Signature Forgery
2001103a-6bbd-11d9-851d-000a95bc6fae imlib -- xpm heap buffer overflows and integer overflows
207f8ff3-f697-11d8-81b0-000347a4fa7d nss -- exploitable buffer overflow in SSLv2 protocol handler
209f0d75-4b5c-11dc-a6cd-000fb5066b20 flyspray -- authentication bypass
20a4eb11-8ea3-11dc-a396-0016179b2dd5 tikiwiki -- multiple vulnerabilities
20be2982-4aae-11d8-96f2-0020ed76ef5a fsp buffer overflow and directory traversal vulnerabilities
20c9bb14-81e6-11d9-a9e7-0001020eed82 opera -- "data:" URI handler spoofing vulnerability
20d16518-2477-11d9-814e-0001020eed82 mpg123 -- buffer overflow in URL handling
20dfd134-1d39-11d9-9be9-000c6e8f12ef freeradius -- denial-of-service vulnerability
21b7c550-2a22-11db-a6e2-000e0c2e438a squirrelmail -- random variable overwrite vulnerability
21c223f2-d596-11da-8098-00123ffe8333 ethereal -- Multiple Protocol Dissector Vulnerabilities
227475c2-09cb-11db-9156-000e0c2e438a webmin, usermin -- arbitrary file disclosure vulnerability
229577a8-0936-11db-bf72-00046151137e phpmyadmin -- cross site scripting vulnerability
22c6b826-cee0-11da-8578-00123ffe8333 plone -- "member_id" Parameter Portrait Manipulation Vulnerability
22f00553-a09d-11d9-a788-0001020eed82 portupgrade -- insecure temporary file handling vulnerability
2328adef-157c-11d9-8402-000d93664d5c racoon -- improper certificate handling
23573650-f99a-11da-994e-00142a5f241c dokuwiki -- multiple vulnerabilities
23afd91f-676b-11da-99f6-00123ffe8333 phpmyadmin -- register_globals emulation "import_blacklist" manipulation
23fb5a04-722b-11d9-9e1e-c296ac722cb3 squid -- buffer overflow in WCCP recvfrom() call
249a8c42-6973-11d9-ae49-000c41e2cdad zgv -- exploitable heap overflows
24eee285-09c7-11da-bc08-0001020eed82 xpdf -- disk fill DoS vulnerability
24f6b1eb-43d5-11db-81e1-000e0c2e438a win32-codecs -- multiple vulnerabilities
2506f558-6a8a-11da-b96e-000fb586ba73 mnemo -- Cross site scripting vulnerabilities in several of the notepad name and note data fields
253ea131-bd12-11d8-b071-00e08110b673 Gallery 1.4.3 and ealier user authentication bypass
25858c37-bdab-11da-b7d4-00123ffe8333 linux-realplayer -- buffer overrun
265c8b00-d2d0-11d8-b479-02e0185c0b53 multiple vulnerabilities in ethereal
2689f4cb-ec4c-11d8-9440-000347a4fa7d rsync -- path sanitizing vulnerability
26a08c77-32da-4dd7-a884-a76fc49aa824 tomcat -- Tomcat Manager cross-site scripting
26c9e8c6-1c99-11d9-814e-0001020eed82 sharutils -- buffer overflows
2701611f-df5c-11d9-b875-0001020eed82 gaim -- Yahoo! remote crash vulnerability
271498a9-2cd4-11da-a263-0001020eed82 clamav -- arbitrary code execution and DoS vulnerabilities
273cc1a3-0d6b-11d9-8a8a-000c41e2cdad lha -- numerous vulnerabilities when extracting archives
2747fc39-915b-11dc-9239-001c2514716c xpdf -- multiple remote Stream.CC vulnerabilities
275b845e-f56c-11db-8163-000e0c2e438a FreeBSD -- IPv6 Routing Header 0 is dangerous
2797b27a-f55b-11d8-81b0-000347a4fa7d kdelibs -- konqueror cross-domain cookie injection
27a70a01-5f6c-11da-8d54-000cf18bbe54 ghostscript -- insecure temporary file creation vulnerability
27c331d5-64c7-11d8-80e3-0020ed76ef5a Vulnerabilities in H.323 implementations
282dfea0-3378-11d9-b404-000c6e8f12ef apache2 multiple space header denial-of-service vulnerability
28ab7ddf-61ab-11d9-a9e7-0001020eed82 dillo -- format string vulnerability
28c9243a-72ed-11da-8c1d-000e0c2e438a phpbb -- multiple vulnerabilities
28e93883-539f-11d9-a9e7-0001020eed82 acroread5 -- mailListIsPdf() buffer overflow vulnerability
290d81b9-80f1-11d8-9645-0020ed76ef5a oftpd denial-of-service vulnerability (PORT command)
299e3f81-aee7-11dc-b781-0016179b2dd5 e2fsprogs -- heap buffer overflow
29dd0065-81fa-11d9-a9e7-0001020eed82 kdelibs -- insecure temporary file creation
29edd807-438d-11d9-8bb9-00065be4b5b6 mysql -- FTS request denial of service vulnerability
2b2b333b-6bd3-11d9-95f8-000a95bc6fae mc -- multiple vulnerabilities
2b4d5288-447e-11d9-9ebb-000854d03344 rockdodger -- buffer overflows
2b6e47b1-0598-11da-86bc-000e0c2e438a ipsec -- Incorrect key usage in AES-XCBC-MAC
2bc96f18-683f-11dc-82b6-02e0185f8d72 samba -- nss_info plugin privilege escalation vulnerability
2bcd2d24-24ca-11d8-82e5-0020ed76ef5a Buffer overflow in pam_smb password handling
2be7c122-0614-11db-9156-000e0c2e438a hashcash -- heap overflow vulnerability
2c25e762-6bb9-11d9-93db-000a95bc6fae quake2 -- multiple critical vulnerabilities
2c4f4688-298b-11dc-a197-0011098b2f36 typespeed -- arbitrary code execution
2c5757f4-88bf-11d9-8720-0007e900f87b sup -- format string vulnerability
2c6acefd-8194-11d8-9645-0020ed76ef5a setsockopt(2) IPv6 sockets input validation error
2c8a84d9-5bee-11db-a5ae-00508d6a62df vtiger -- multiple remote file inclusion vulnerabilities
2d2dcbb4-906c-11dc-a951-0016179b2dd5 phpmyadmin -- cross-site scripting vulnerability
2d8cf857-81ea-11d9-a9e7-0001020eed82 gftp -- directory traversal vulnerability
2d9ad236-4d26-11db-b48d-00508d6a62df freeciv -- Denial of Service Vulnerabilities
2db97aa6-be81-11da-9b82-0050bf27ba24 horde -- remote code execution vulnerability in the help viewer
2dc764fa-40c0-11dc-aeac-02e0185f8d72 FreeBSD -- Buffer overflow in tcpdump(1)
2de14f7a-dad9-11d8-b59a-00061bc2ad93 Multiple Potential Buffer Overruns in Samba
2df297a2-dc74-11da-a22b-000c6ec775d9 awstats -- arbitrary command execution vulnerability
2e116ba5-f7c3-11d9-928e-000b5d7e6dd5 kdebase -- Kate backup file permission leak
2e129846-8fbb-11d8-8b29-0020ed76ef5a MySQL insecure temporary file creation (mysqlbug)
2e25d38b-54d1-11d9-b612-000c6e8f12ef jabberd -- denial-of-service vulnerability
2e28cefb-2aee-11da-a263-0001020eed82 firefox & mozilla -- command line URL shell command injection
2ecd02e2-e864-11da-b9f4-00123ffe8333 phpmyadmin -- XSRF vulnerabilities
2f0cb4bb-416d-11da-99fe-000854d03344 xloadimage -- buffer overflows in NIFF image title handling
2fbe16c2-cab6-11d9-9aed-000e0c2e438a freeradius -- sql injection and denial of service vulnerability
3030ae22-1c7f-11d9-81a4-0050fc56d258 mail-notification -- denial-of-service vulnerability
30394651-13e1-11dd-bab7-0016179b2dd5 gnupg -- memory corruption vulnerability
30866e6c-3c6d-11dd-98c9-00163e000016 vim -- Vim Shell Command Injection Vulnerabilities
30acb8ae-9d46-11dc-9114-001c2514716c rubygem-rails -- session-fixation vulnerability
30c560ff-e0df-11dc-891a-02061b08fc24 opera -- multiple vulnerabilities
30cea6be-1d0c-11d9-814e-0001020eed82 CUPS -- local information disclosure
30cf9485-1c2c-11d9-9ecb-000c6e8f12ef zinf -- potential buffer overflow playlist support
30e4ed7b-1ca6-11da-bc01-000e0c2e438a bind9 -- denial of service
30f5ca1d-a90b-11dc-bf13-0211060005df qemu -- Translation Block Local Denial of Service Vulnerability
310d0087-0fde-4929-a41f-96f17c5adffe xloadimage -- arbitrary command execution when handling compressed files
31435fbc-ae73-11dc-a5f9-001a4d49522b peercast -- buffer overflow vulnerability
316e1c9b-671c-11d8-9aad-000a95bc6fae hsftp format string vulnerabilities
31952117-3d17-11d9-8818-008088034841 Cyrus IMAPd -- APPEND command uses undefined programming construct
31b045e7-ae75-11dc-a5f9-001a4d49522b opera -- multiple vulnerabilities
31d9fbb4-9d09-11dc-a29d-0016d325a0ed ikiwiki -- improper symlink verification vulnerability
322d4ff6-85c3-11d8-a41f-0020ed76ef5a Midnight Commander buffer overflow during symlink resolution
323784cf-48a6-11d9-a9e7-0001020eed82 viewcvs -- information leakage
3243e839-f489-11d8-9837-000c41e2cdad fidogate -- write files as `news' user
326c517a-d029-11d9-9aed-000e0c2e438a phpbb -- multiple vulnerabilities
32d38cbb-2632-11dc-94da-0016179b2dd5 flac123 -- stack overflow in comment parsing
32d4f0f1-85c3-11d9-b6dc-0007e900f747 mkbold-mkitalic -- format string vulnerability
32db37a5-50c3-11db-acf3-000c6ec775d9 openssh -- multiple vulnerabilities
3388eff9-5d6e-11d8-80e3-0020ed76ef5a Samba 3.0.x password initialization bug
338d1723-5f03-11d9-92a7-000bdb1444a4 horde -- XSS vulnerabilities
339fbbc1-4d23-11db-b48d-00508d6a62df freeciv -- Packet Parsing Denial of Service Vulnerability
33ab4a47-bfc1-11d8-b00e-000347a4fa7d Several vulnerabilities found in PHPNuke
34134fd4-5d81-11d8-80e3-0020ed76ef5a pine insecure URL handling
342d2e48-26db-11db-9275-000475abc56f clamav -- heap overflow vulnerability
34414a1e-e377-11db-b8ab-000c76189c4c zope -- cross-site scripting vulnerability
3497d7be-2fef-45f4-8162-9063751b573a fetchmail -- remote root/code injection from malicious POP3 server
34c93ae8-7e6f-11db-bf00-02e081235dab gnupg -- buffer overflow
350a5bd9-520b-11db-8f1a-000a48049292 MT -- Search Unspecified XSS
3546a833-03ea-11dc-a51d-0019b95d4f14 samba -- multiple vulnerabilities
35e54755-54e4-11dd-ad8b-0030843d3802 phpmyadmin -- cross site request forgery vulnerabilites
35f2679f-52d7-11db-8f1a-000a48049292 postnuke -- admin section SQL injection
35f6093c-73c3-11d9-8a93-00065be4b5b6 newsgrab -- directory traversal vulnerability
35f6fdf8-a425-11d8-9c6d-0020ed76ef5a Cyrus IMAP pre-authentication heap overflow vulnerability
36494478-6a88-11da-b96e-000fb586ba73 kronolith -- Cross site scripting vulnerabilities in several of the calendar name and event data fields
37a5c10f-bf56-11da-b0e9-00123ffe8333 freeradius -- EAP-MSCHAPv2 Authentication Bypass
37e30313-9d8c-11db-858b-0060084a00e5 fetchmail -- crashes when refusing a message bound for an MDA
3837f462-5d6b-11d8-80e3-0020ed76ef5a Buffer overflows in XFree86 servers
3897a2f8-1d57-11d9-bc4a-000c41e2cdad tiff -- multiple integer overflows
38c76fcf-1744-11da-978e-0001020eed82 pam_ldap -- authentication bypass vulnerability
392b5b1d-9471-11dc-9db7-001c2514716c php -- multiple security vulnerabilities
396ee517-a607-11d9-ac72-000bdb1444a4 horde -- Horde Page Title Cross-Site Scripting Vulnerability
39953788-6bbb-11d9-8bc9-000a95bc6fae egroupware -- arbitrary file download in JiNN
39988ee8-1918-11dc-b6bd-0016179b2dd5 cups -- Incomplete SSL Negotiation Denial of Service
39bd57e6-5d83-11d8-80e3-0020ed76ef5a pine remotely exploitable vulnerabilities
3a408f6f-9c52-11d8-9366-0020ed76ef5a libpng denial-of-service
3a81017a-8154-11dc-9283-0016179b2dd5 ldapscripts -- Command Line User Credentials Disclosure
3ac80dd2-14df-11dc-bcfc-0016179b2dd5 mplayer -- cddb stack overflow
3b260179-e464-460d-bf9f-d5cda6204020 racoon -- remote denial-of-service
3b3676be-52e1-11d9-a9e7-0001020eed82 samba -- integer overflow vulnerability
3b4a6982-0b24-11da-bc08-0001020eed82 libgadu -- multiple vulnerabilities
3b7c7f6c-7102-11d8-873f-0020ed76ef5a wu-ftpd ftpaccess `restricted-uid'/`restricted-gid' directive may be bypassed
3bc5691e-38dd-11da-92f5-020039488e34 libxine -- format string vulnerability
3bf157fa-e1c6-11d9-b875-0001020eed82 sudo -- local race condition vulnerability
3cb6f059-c69d-11db-9f82-000e0c2e438a bind -- Multiple Denial of Service vulnerabilities
3cb88bb2-67a6-11d8-80e3-0020ed76ef5a mailman XSS in admin script
3cc84400-6576-11d9-a9e7-0001020eed82 mpg123 -- buffer overflow vulnerability
3ce8c7e2-66cf-11dc-b25f-02e0185f8d72 mozilla -- code execution via Quicktime media-link files
3d0e724e-129b-11dc-9f79-0016179b2dd5 phppgadmin -- cross site scripting vulnerability
3d1e9267-073f-11d9-b45d-000c41e2cdad gdk-pixbuf -- image decoding vulnerabilities
3d8d3548-9d02-11db-a541-000ae42e9b93 drupal -- multiple vulnerabilities
3dd7eb58-80ae-11db-b4ec-000854d03344 gtar -- GNUTYPE_NAMES directory traversal vulnerability
3de342fb-40be-11dc-aeac-02e0185f8d72 FreeBSD -- Predictable query ids in named(8)
3de49331-0dec-422c-93e5-e4719e9869c5 openvpn -- potential denial-of-service on servers in TCP mode
3e0072d4-d05b-11d9-9aed-000e0c2e438a net-snmp -- fixproc insecure temporary file creation
3e3c860d-7dae-11d9-a9e7-0001020eed82 emacs -- movemail format string vulnerability
3e4ffe76-e0d4-11d8-9b0a-000347a4fa7d SoX buffer overflows when handling .WAV files
3e9be8c4-8192-11d8-9645-0020ed76ef5a ecartis buffer overflows and input validation bugs
3ec8f43b-e8ef-11d9-b875-0001020eed82 kernel -- TCP connection stall denial of service
3f4ac724-fa8b-11d9-afcf-0060084a00e5 fetchmail -- denial of service/crash from malicious POP3 server
3f851b22-89fb-11db-a937-003048116330 proftpd -- remote code execution vulnerabilities
3fa2b372-a9f5-11d9-a788-0001020eed82 gaim -- remote DoS on receiving malformed HTML
3fbf9db2-658b-11d9-abad-000a95bc6fae mozilla -- heap overflow in NNTP handler
400d9d22-d6c5-11da-a14b-00123ffe8333 trac -- Wiki Macro Script Insertion Vulnerability
402ae710-26a2-11dd-ae05-825f4c35000a peercast -- arbitrary code execution
40549bbf-43b5-11d9-a9e7-0001020eed82 zip -- long path buffer overflow
40856a51-e1d9-11d9-b875-0001020eed82 opera -- "javascript:" URL cross-site scripting vulnerability
408f6ebf-d152-11da-962f-000b972eb521 cyrus-sasl -- DIGEST-MD5 Pre-Authentication Denial of Service
40a0185f-ec32-11da-be02-000c6ec775d9 drupal -- multiple vulnerabilities
40a3bca2-6809-11d9-a9e7-0001020eed82 cups-base -- HPGL buffer overflow vulnerability
40fcf20f-8891-11d8-90d1-0020ed76ef5a racoon remote denial of service vulnerability (IKE Generic Payload Header)
41da2ba4-a24e-11db-bd24-000f3dcc6a5d cacti -- Multiple vulnerabilities
4238151d-207a-11d9-bfe2-0090962cff2a mod_ssl -- SSLCipherSuite bypass
4260eacb-26b8-11d9-9289-000c41e2cdad gaim -- multiple buffer overflows
429249d2-67a7-11d8-80e3-0020ed76ef5a mailman XSS in create script
432bf98d-9e25-11da-b410-000e0c2e438a kpdf -- heap based buffer overflow
43770b1c-72f6-11da-8c1d-000e0c2e438a nbd-server -- buffer overflow vulnerability
43a7b0a7-f9bc-11d9-b473-00061bc2ad93 PowerDNS -- LDAP backend fails to escape all queries
43cb40b3-c8c2-11da-a672-000e0c2e438a f2c -- insecure temporary files
44224e08-8306-11dc-9283-0016179b2dd5 opera -- multiple vulnerabilities
44449bf7-c69b-11db-9f82-000e0c2e438a gtar -- name mangling symlink vulnerability
4451a4c9-c05e-11dc-982e-001372fd0af2 drupal -- cross site request forgery
446dbecb-9edc-11d8-9366-0020ed76ef5a heimdal kadmind remote heap buffer overflow
44c8694a-12f9-11dd-9b26-001c2514716c extman -- password bypass vulnerability
44e5f5bd-4d76-11da-bf37-000fb586ba73 pear-PEAR -- PEAR installer arbitrary code execution vulnerability
44e7764c-2614-11da-9e1e-c296ac722cb3 squid -- possible denial of service condition regarding NTLM authentication
44fb0302-9d38-11dc-9114-001c2514716c rubygem-rails -- JSON XSS vulnerability
450b76ee-5068-11db-a5ae-00508d6a62df dokuwiki -- multiple vulnerabilities
45500f74-5947-11dc-87c1-000e2e5785ad fetchmail -- denial of service on reject of local warning message
4593cb09-4c81-11d9-983e-000c6e8f12ef konqueror -- Password Disclosure for SMB Shares
45b75152-ae5f-11d9-a788-0001020eed82 mozilla -- javascript "lambda" replace exposes memory contents
4645b98c-e46e-11da-9ae7-00123fcc6e5c vnc - authentication bypass vulnerability
46b922a8-c69c-11db-9f82-000e0c2e438a FreeBSD -- Jail rc.d script privilege escalation
46f7b598-a781-11da-906a-fde5cdde365e bugzilla -- multiple vulnerabilities
47bdabcf-3cf9-11da-baa2-0004614cc33d gallery2 -- file disclosure vulnerability
4867ae85-608d-11db-8faf-000c6ec775d9 opera -- URL parsing heap overflow vulnerability
486aff57-9ecd-11da-b410-000e0c2e438a postgresql -- character conversion and tsearch2 vulnerabilities
4872d9a7-4128-11dc-bdb0-0016179b2dd5 joomla -- multiple vulnerabilities
48a59c96-9c6e-11d9-a040-000a95bc6fae wine -- information disclosure due to insecure temporary file handling
4913886c-e875-11da-b9f4-00123ffe8333 MySQL -- Information Disclosure and Buffer Overflow Vulnerabilities
492f8896-70fa-11d8-873f-0020ed76ef5a Apache 2 mod_ssl denial-of-service
498a8731-7cfc-11dc-96e6-0012f06707f0 phpmyadmin -- cross-site scripting vulnerability
49ad1bf8-5d7e-11d8-80e3-0020ed76ef5a ChiTeX/ChiLaTeX unsafe set-user-id root
4a0b334d-8d8d-11d9-afa0-003048705d5a phpbb - Insuffient check against HTML code in usercp_register.php
4a338d17-412d-11dc-bdb0-0016179b2dd5 fsplib -- multiple vulnerabilities
4aab7bcd-b294-11dc-a6f0-00a0cce0781e gallery2 -- multiple vulnerabilities
4aec9d58-ce7b-11d8-858d-000d610a3b12 Format string vulnerability in SSLtelnet
4afacca1-eb9d-11d9-a8bd-000cf18bbe54 phpbb -- remote PHP code execution vulnerability
4b673ae7-5f9a-11dc-84dd-000102cc8983 lighttpd -- FastCGI header overrun in mod_fastcgi
4bfcd857-c628-11da-b2fb-000e0c2e438a kaffeine -- buffer overflow vulnerability
4c005a5e-2541-4d95-80a0-00c76919aa66 fd_set -- bitmap index overflow in multiple applications
4cb9c513-03ef-11dc-a51d-0019b95d4f14 png -- DoS crash vulnerability
4d49f4ba-071f-11d9-b45d-000c41e2cdad apache -- ap_resolve_env buffer overflow
4d837296-cc28-11d8-a54c-02e0185c0b53 GNATS local privilege elevation
4db1669c-8589-11db-ac4f-02e081235dab gnupg -- remotely controllable function pointer
4e210d72-1c5c-11da-92ce-0048543d60ce squid -- Denial Of Service Vulnerability in sslConnectTimeout
4e4bd2c2-6bd5-11d9-9e1e-c296ac722cb3 squid -- HTTP response splitting cache pollution attack
4fb43b2f-46a9-11dd-9d38-00163e000016 FreeType 2 -- Multiple Vulnerabilities
5039ae61-2c9f-11db-8401-000ae42e9b93 globus -- Multiple tmpfile races
50457509-d05e-11d9-9aed-000e0c2e438a phpSysInfo -- cross site scripting vulnerability
50744596-368f-11d9-a9e7-0001020eed82 proxytunnel -- format string vulnerability
51436b4c-1250-11dd-bab7-0016179b2dd5 postgresql -- multiple vulnerabilities
5192e7ca-7d4f-11d9-a9e7-0001020eed82 mod_python -- information leakage vulnerability
51b51d4a-7c0f-11dc-9e47-0011d861d5e2 phpmyadmin -- cross-site scripting vulnerability
5238ac45-9d8c-11db-858b-0060084a00e5 fetchmail -- TLS enforcement problem/MITM attack/password exposure
523fad14-eb9d-11d9-a8bd-000cf18bbe54 pear-XML_RPC -- arbitrary remote code execution
52ba7713-9d42-11da-8c1d-000e0c2e438a pf -- IP fragment handling panic
5360a659-131c-11d9-bc4a-000c41e2cdad mozilla -- hostname spoofing bug
53802164-3f7e-11dd-90ea-0019666436c2 ruby -- multiple integer and buffer overflow vulnerabilities
53e711ed-8972-11d9-9ff8-00306e01dda2 phpbb -- privilege elevation and path disclosure
55041d37-ff62-11d9-a9a5-000ae4641456 jabberd -- 3 buffer overflows
553224e7-4325-11d9-a3d5-000c6e8f12ef jabberd -- remote buffer overflow vulnerability
555ac165-2bee-11dd-bbdc-00e0815b8da8 spamdyke -- open relay
562a3fdf-16d6-11d9-bc4a-000c41e2cdad php -- vulnerability in RFC 1867 file upload processing
562cf6c4-b9f1-11dc-a302-000102cc8983 linux-flashplugin -- multiple vulnerabilities
5678da43-ea99-11db-a802-000fea2763ce lighttpd -- DOS when access files with mtime 0
56971fa6-641c-11d9-a097-000854d03344 xshisen -- local buffer overflows
5729b8ed-5d75-11d8-80e3-0020ed76ef5a rsync buffer overflow in server mode
5752a0df-60c5-4876-a872-f12f9a02fa05 gallery -- cross-site scripting
5789a92e-5d7f-11d8-80e3-0020ed76ef5a pine remotely exploitable buffer overflow in newmail.c
57a0242d-8c4e-11da-8ddf-000ae42e9b93 sge -- local root exploit in bundled rsh executable
57ae52f7-b9cc-11db-bf0f-0013720b182d samba -- format string bug in afsacl.so VFS plugin
57c705d6-12ae-11dd-bab7-0016179b2dd5 png -- unknown chunk processing uninitialized memory access
58247a96-01c8-11da-bc08-0001020eed82 phpmyadmin -- cross site scripting vulnerability
589d8053-0b03-11dd-b4ef-00e07dc4ec84 clamav -- Multiple Vulnerabilities
58fc2752-5f74-11d9-a9e7-0001020eed82 pcal -- buffer overflow vulnerabilities
592815da-9eed-11da-b410-000e0c2e438a mantis -- "view_filters_page.php" cross site scripting vulnerability
594ad3c5-a39b-11da-926c-0800209adf0e SSH.COM SFTP server -- format string vulnerability
594eb447-e398-11d9-a8bd-000cf18bbe54 ruby -- arbitrary command execution on XMLRPC server
597e2bee-68ea-11d9-a9e7-0001020eed82 ImageMagick -- PSD handler heap overflow vulnerability
59ada6e5-676a-11da-99f6-00123ffe8333 phpmyadmin -- XSS vulnerabilities
5a39a22e-5478-11db-8f1a-000a48049292 mono -- "System.CodeDom.Compiler" Insecure Temporary Creation
5a5422fd-7e1a-11d9-a9e7-0001020eed82 powerdns -- DoS vulnerability
5a945904-73b1-11db-91d2-0002a5c2f4ef unzoo -- Directory Traversal Vulnerability
5abfee2d-5d82-11d8-80e3-0020ed76ef5a pine remote denial-of-service attack
5ad3e437-e527-4514-b9ed-280b2ca1a8c9 openvpn -- multiple TCP clients connecting with the same certificate at the same time can crash the server
5b47b70d-8ba9-11db-81d5-00123ffe8333 dbus -- match_rule_equal() Weakness
5b47c279-8cb5-11dc-8878-0016179b2dd5 perl -- regular expressions unicode data buffer overflow
5b8f9a02-ec93-11d8-b913-000c41e2cdad gaim remotely exploitable vulnerabilities in MSN component
5bf1a715-cc57-440f-b0a5-6406961c54a7 squid -- denial-of-service vulnerabilities
5c554c0f-c69a-11db-9f82-000e0c2e438a FreeBSD -- Kernel memory disclosure in firewire(4)
5c7bb4dd-6a56-11d9-97ec-000c6e8f12ef konversation -- shell script command injection
5c9a2769-5ade-11db-a5ae-00508d6a62df google-earth -- heap overflow in the KML engine
5d36ef32-a9cf-11d8-9c6d-0020ed76ef5a subversion date parsing vulnerability
5d425189-7a03-11d9-a9e7-0001020eed82 postgresql -- privilege escalation vulnerability
5d51d245-00ca-11da-bc08-0001020eed82 ethereal -- multiple protocol dissectors vulnerabilities
5d72701a-f601-11d9-bcd1-02061b08fc24 firefox & mozilla -- multiple vulnerabilities
5e7f58c3-b3f8-4258-aeb8-795e5e940ff8 mplayer heap overflow in http requests
5e92e8a2-5d7b-11d8-80e3-0020ed76ef5a icecast 1.x multiple vulnerabilities
5ebfe901-a3cb-11d9-b248-000854d03344 hashcash -- format string vulnerability
5ef12755-1c6c-11dd-851d-0016d325a0ed swfdec -- exposure of sensitive information
5f003a08-ba3c-11d9-837d-000e0c2e438a sharutils -- unshar insecure temporary file creation
5f29c2e4-9f6a-11d8-abbc-00e08110b673 exim buffer overflow when verify = header_syntax is used
5f2a0c40-1322-11db-bd23-000475abc56f zope -- information disclosure vulnerability
5fde5c30-0f4e-11da-bc01-000e0c2e438a tor -- diffie-hellman handshake flaw
5fe7e27a-64cb-11d9-9e1e-c296ac722cb3 squid -- denial of service with forged WCCP messages
603fe36d-ec9d-11d8-b913-000c41e2cdad kdelibs insecure temporary file handling
60e1792b-c380-11dc-821a-000bcdc1757a geeklog xss vulnerability
60e26a40-3b25-11da-9484-00123ffe8333 openssl -- potential SSL 2.0 rollback
60f8fe7b-3cfb-11da-baa2-0004614cc33d webcalendar -- remote file inclusion vulnerability
6107efb9-aae3-11da-aea1-000854d03344 gtar -- invalid headers buffer overflow
610bc692-a2ad-11dc-900c-000bcdc1757a GNU finger vulnerability
6111ecb8-b20d-11da-b2fb-000e0c2e438a nfs -- remote denial of service
6129fdc7-6462-456d-a3ef-8fc3fbf44d16 openvpn -- arbitrary code execution on client through malicious or compromised server
612a34ec-81dc-11da-a043-0002a5c3d308 clamav -- possible heap overflow in the UPX code
61349f77-c620-11da-b2fb-000e0c2e438a thunderbird -- javascript execution
61480a9a-22b2-11d9-814e-0001020eed82 cabextract -- insecure directory handling
61534682-b8f4-11da-8e62-000e0c33c2dc xorg-server -- privilege escalation
616cf823-f48b-11d8-9837-000c41e2cdad courier-imap -- format string vulnerability in debug mode
617a4021-8bf0-11dc-bffa-0016179b2dd5 perdition -- str_vwrite format string vulnerability
6192ae3d-9595-11d9-a9e0-0001020eed82 phpmyadmin -- increased privilege vulnerability
619ef337-949a-11d9-b813-00d05964249f mysql-server -- multiple remote vulnerabilities
62239968-2f2a-11d9-a9e7-0001020eed82 gd -- integer overflow
624fe633-9006-11d9-a22c-0001020eed82 libexif -- buffer overflow vulnerability
62b8f253-12d9-11dc-a35c-001485ab073e typo3 -- email header injection
632c98be-aad2-4af2-849f-41a6862afd6a p5-Imager - possibly exploitable buffer overflow
63347ee7-6841-11dc-82b6-02e0185f8d72 wordpress -- remote sql injection vulnerability
633716fa-1f8f-11dd-b143-0211d880e350 vorbis-tools -- Speex header processing vulnerability
635bf5f4-26b7-11d9-9289-000c41e2cdad gaim -- malicious smiley themes
63bd4bad-dffe-11d9-b875-0001020eed82 gzip -- directory traversal and permission race vulnerabilities
63fe4189-9f97-11da-ac32-0001020eed82 gnupg -- false positive signature verification
641859e8-eca1-11d8-b913-000c41e2cdad Mutiple browser frame injection vulnerability
641e8609-cab5-11d9-9aed-000e0c2e438a ppxp -- local root exploit
64bf6234-520d-11db-8f1a-000a48049292 gnutls -- RSA Signature Forgery Vulnerability
64c8cc2a-59b1-11d9-8a99-000c6e8f12ef libxine -- buffer-overflow vulnerability in aiff support
651996e0-fe07-11d9-8329-000e0c2e438a apache -- http request smuggling
655ee1ec-511b-11dd-80ba-000bcdf0a03b FreeBSD -- DNS cache poisoning
6596bb80-d026-11d9-9aed-000e0c2e438a shtool -- insecure temporary file creation
65a17a3f-ed6e-11d8-aff1-00061bc2ad93 Arbitrary code execution via a format string vulnerability in jftpgw
65a8f773-4a37-11db-a4cc-000a48049292 zope -- restructuredText "csv_table" Information Disclosure
65c8ecf9-2adb-11db-a6e2-000e0c2e438a postgresql -- multiple vulnerabilities
65e99f52-1c5f-11d9-bc4a-000c41e2cdad squid -- SNMP module denial-of-service vulnerability
666b8c9e-8212-11db-851e-0016179b2dd5 tdiary -- cross site scripting vulnerability
66dbb2ee-99b8-45b2-bb3e-640caea67a60 leafnode -- fetchnews denial-of-service triggered by transmission abort/timeout
6738977b-e9a5-11da-b9f4-00123ffe8333 coppermine -- "file" Local File Inclusion Vulnerability
673aec6f-1cae-11da-bc01-000e0c2e438a htdig -- cross site scripting vulnerability
67710833-1626-11d9-bc4a-000c41e2cdad Boundary checking errors in syscons
6779e82f-b60b-11da-913d-000ae42e9b93 drupal -- multiple vulnerabilities
67bd39ba-12b5-11dd-bab7-0016179b2dd5 firefox -- javascript garbage collector vulnerability
67c05283-5d62-11d8-80e3-0020ed76ef5a Buffer overflow in Mutt 1.4
67dbe99f-0f09-11db-94f8-00e029485e38 shoutcast -- cross-site scripting, information exposure
6821a2db-4ab7-11da-932d-00055d790c25 PHP -- multiple vulnerabilities