OpenBSD VuXML

Documenting security issues in the OpenBSD Ports & Packages Collection

Security issues that affect the OpenBSD Ports & Packages Collection are documented using the Vulnerabilities and Exposures Markup Language (VuXML). The current VuXML document that serves as the source for the content of this site can be found:

entry date index


Entered Topic
2006-01-10 clamav -- heap overflow in the UPX code
2005-10-07 imap-uw -- buffer verflow vulnerability
2005-08-23 openvpn -- several vulnerabilities
2005-08-22 pcre -- heap overflow
2005-08-20 acroread -- buffer overflow
2005-08-17 gaim -- remote execution of arbitrary code
2005-08-09 tor -- critical security bug
2005-08-02 jabberd -- buffer overflow vulnerabilities
2005-07-28 opera -- multiple vulnerabilities
2005-07-27 clamav -- multiple buffer overflows
vim -- modelines execute arbitrary shell code
2005-07-25 fetchmail -- remote code injection vulnerability
2005-07-12 php4-pear -- PHP script injection vulnerability
2005-07-10 p5-Mail-SpamAssassin -- denial of service vulnerability
2005-07-02 tor -- server disregards exit policies
2005-07-01 ruby -- arbitrary command execution on XMLRPC server
2005-06-28 clamav -- denial of service vulnerability
2005-06-22 tor -- information disclosure vunlerability
2005-06-09 leafnode -- denial of service vulnerability
2005-05-25 net-snmp -- fixproc insecure temporary file creation
squid -- multiple vulnerabilities
2005-05-19 nasm -- multiple vulnerabilities
2005-05-13 gaim -- multiple vulnerabilities
2005-05-11 gnutls -- denial of service vulnerability
2005-05-05 leafnode -- denial of service vulnerability
2005-05-01 ImageMagick -- ReadPNMImage() heap overflow vulnerability
2005-04-27 p5-Convert-UUlib -- buffer overflow
2005-04-12 xv -- multiple buffer overflows
2005-04-11 rsnapshot -- local privilege escalation
2005-04-07 gaim -- multiple vulnerabilities
2005-04-04 php4 -- multiple vulnerabilities
php5 -- multiple vulnerabilities
sylpheed -- message reply buffer overflow vulnerability
2005-03-27 gnupg -- OpenPGP protocol attack
tiff -- multiple vulnerabilities
2005-03-23 jabberd -- multiple vulnerabilities
2005-03-22 grip -- CDDB response multiple matches buffer overflow vulnerability
2005-03-15 xv -- filename handling vulnerability
2005-03-14 curl -- authentication buffer overflow vulnerability
2005-03-13 libexif -- buffer overflow vulnerability
2005-03-11 mlterm -- integer overflow vulnerability
2005-02-22 unace -- multiple buffer overflows
2005-02-17 mc -- multiple vulnerabilities
2005-02-11 enscript -- multiple vulnerabilities
gcpio -- broken file permissions
2005-02-10 mailman -- directory traversal vulnerability
2005-02-09 (X)emacs -- format string vulnerability
2005-02-05 opera -- Data URLs with executables and misleading download dialog
postgresql -- privilege escalation via LOAD
2005-01-31 dante -- fd_set structure bitmap array index overflow
2005-01-30 evolution -- arbitrary code execution vulnerability
2005-01-29 imap-uw -- inappropriate user authentication (CRAM-MD5)
2005-01-26 exim -- two buffer overflow vulnerabilities
mailman -- cross-site scripting vulnerability
squid -- several vulnerabilites
2005-01-24 mod_auth_radius -- remote integer overflow
2005-01-22 cups -- stack overflow in included xpdf code
2005-01-19 mysql-server -- mysqlaccess insecure temporary file creation
xpdf -- multiple stack overflows in makeFileKey2();
2005-01-17 unrtf -- buffer overflow vulnerability
2005-01-02 gnomevfs -- unsafe URI handling
2004-12-25 tetex -- buffer overflow vunerability in included xpdf
2004-12-22 acroread -- mailListIsPdf() buffer overflow vulnerability
mplayer -- multiple overflow vulnerabilites
xpdf -- buffer overflow vunerability
2004-12-20 php5 -- multiple vulnerabilities
2004-12-18 opera -- multiple vulnerabilities
php4 -- multiple vulnerabilities
2004-12-04 zip -- long path buffer overflow
2004-11-10 bnc -- buffer overflow vulnerability
2004-10-23 cabextract -- directory-traversal issue
xpdf -- integer overflow vulnerabilities
2004-10-22 gaim -- DOS and buffer overflow vulnerabilities
2004-10-20 squid -- SNMP related denial of service
2004-10-16 bnc -- input validation flaw
icecast -- HTTP header overflow
2004-10-08 cyrus-sasl -- dynamic library loading and set-user-ID applications
2004-08-25 kdelibs -- konqueror cross-domain cookie injection
2004-08-20 mysql-server -- insecure file creation in mysqlhotcopy
2004-08-17 ruby -- insecure file permissions
2004-08-14 rsync -- path-sanitizing bug that affects daemon mode if chroot is disabled
2004-08-12 jftpgw -- format string vulnerability
2004-08-04 png -- stack-based buffer overflow and other code concerns
2004-07-31 sox -- buffer overflows while handling malicious WAV files
2004-07-23 samba -- potential buffer overrun with 'mangling method = hash'
2004-07-15 php4 -- memory_limit remote vulnerability
2004-07-07 opera -- frame injection vulnerability
png -- buffer overflow vulnerability on the row buffers
2004-06-20 pure-ftpd -- potential DoS when maximum connections is reached
2004-06-19 aspell -- buffer overflow in word-list-compress
2004-05-31 mailman -- member password disclosure vulnerability
2004-05-19 cadaver -- buffer overflow in included libneon
neon -- buffer overflow
2004-05-15 opera -- telnet URI handler file creation/truncation vulnerability
2004-05-10 exim -- buffer overflow when verify = header_syntax is used
2004-05-06 lha -- buffer overflows and path traversal issues
mplayer -- buffer overflow in Real RTSP streaming
xonix -- failure to drop privileges
2004-05-03 libpng -- out of bound access
2004-04-16 neon -- format string vulnerabilities
2004-04-15 mysql -- insecure temporary file creation
2004-04-14 cadaver -- format string vulnerabilities
2004-04-13 monit -- multiple vulnerabilities
2004-03-30 mplayer -- heap overflow in http requests
2004-03-03 squid -- ACL bypass due to URL decoding bug