OpenBSD VuXML

Documenting security issues in the OpenBSD Ports & Packages Collection

Security issues that affect the OpenBSD Ports & Packages Collection are documented using the Vulnerabilities and Exposures Markup Language (VuXML). The current VuXML document that serves as the source for the content of this site can be found:

modified date index


Modified Topic
2006-01-10 clamav -- heap overflow in the UPX code
2005-10-07 imap-uw -- buffer verflow vulnerability
2005-08-23 openvpn -- several vulnerabilities
2005-08-22 pcre -- heap overflow
2005-08-20 acroread -- buffer overflow
2005-08-17 gaim -- remote execution of arbitrary code
2005-08-09 tor -- critical security bug
2005-08-02 jabberd -- buffer overflow vulnerabilities
2005-07-28 opera -- multiple vulnerabilities
2005-07-27 vim -- modelines execute arbitrary shell code
clamav -- multiple buffer overflows
2005-07-25 fetchmail -- remote code injection vulnerability
2005-07-12 php4-pear -- PHP script injection vulnerability
2005-07-10 p5-Mail-SpamAssassin -- denial of service vulnerability
2005-07-02 tor -- server disregards exit policies
2005-07-01 ruby -- arbitrary command execution on XMLRPC server
2005-06-28 clamav -- denial of service vulnerability
2005-06-22 tor -- information disclosure vunlerability
2005-06-09 leafnode -- denial of service vulnerability
2005-05-25 squid -- multiple vulnerabilities
net-snmp -- fixproc insecure temporary file creation
2005-05-19 nasm -- multiple vulnerabilities
2005-05-13 gaim -- multiple vulnerabilities
2005-05-11 gnutls -- denial of service vulnerability
2005-05-05 leafnode -- denial of service vulnerability
2005-05-01 ImageMagick -- ReadPNMImage() heap overflow vulnerability
2005-04-27 p5-Convert-UUlib -- buffer overflow
2005-04-12 xv -- multiple buffer overflows
2005-04-11 rsnapshot -- local privilege escalation
2005-04-07 gaim -- multiple vulnerabilities
2005-04-04 php4 -- multiple vulnerabilities
php5 -- multiple vulnerabilities
sylpheed -- message reply buffer overflow vulnerability
2005-03-27 gnupg -- OpenPGP protocol attack
tiff -- multiple vulnerabilities
2005-03-23 jabberd -- multiple vulnerabilities
2005-03-22 grip -- CDDB response multiple matches buffer overflow vulnerability
2005-03-15 xv -- filename handling vulnerability
2005-03-14 curl -- authentication buffer overflow vulnerability
2005-03-13 libexif -- buffer overflow vulnerability
2005-03-11 mlterm -- integer overflow vulnerability
2005-02-22 unace -- multiple buffer overflows
2005-02-21 sox -- buffer overflows while handling malicious WAV files
samba -- potential buffer overrun with 'mangling method = hash'
php4 -- memory_limit remote vulnerability
2005-02-17 mc -- multiple vulnerabilities
2005-02-11 gcpio -- broken file permissions
enscript -- multiple vulnerabilities
2005-02-10 mailman -- directory traversal vulnerability
2005-02-09 (X)emacs -- format string vulnerability
2005-02-05 postgresql -- privilege escalation via LOAD
opera -- Data URLs with executables and misleading download dialog
2005-01-31 dante -- fd_set structure bitmap array index overflow
2005-01-30 evolution -- arbitrary code execution vulnerability
2005-01-29 imap-uw -- inappropriate user authentication (CRAM-MD5)
2005-01-26 squid -- several vulnerabilites
exim -- two buffer overflow vulnerabilities
mailman -- cross-site scripting vulnerability
2005-01-24 mod_auth_radius -- remote integer overflow
2005-01-22 cups -- stack overflow in included xpdf code
2005-01-19 xpdf -- multiple stack overflows in makeFileKey2();
mysql-server -- mysqlaccess insecure temporary file creation
2005-01-17 unrtf -- buffer overflow vulnerability
2005-01-02 gnomevfs -- unsafe URI handling
2004-12-25 tetex -- buffer overflow vunerability in included xpdf
2004-12-22 mplayer -- multiple overflow vulnerabilites
xpdf -- buffer overflow vunerability
acroread -- mailListIsPdf() buffer overflow vulnerability
2004-12-20 php5 -- multiple vulnerabilities
2004-12-18 php4 -- multiple vulnerabilities
opera -- multiple vulnerabilities
2004-12-04 zip -- long path buffer overflow
2004-11-10 bnc -- buffer overflow vulnerability
2004-10-23 cabextract -- directory-traversal issue
xpdf -- integer overflow vulnerabilities
2004-10-22 gaim -- DOS and buffer overflow vulnerabilities
2004-10-20 squid -- SNMP related denial of service
2004-10-16 bnc -- input validation flaw
icecast -- HTTP header overflow
2004-10-08 cyrus-sasl -- dynamic library loading and set-user-ID applications
2004-08-25 kdelibs -- konqueror cross-domain cookie injection
2004-08-20 mysql-server -- insecure file creation in mysqlhotcopy
2004-08-17 ruby -- insecure file permissions
2004-08-14 rsync -- path-sanitizing bug that affects daemon mode if chroot is disabled
2004-08-12 jftpgw -- format string vulnerability
2004-08-05 png -- stack-based buffer overflow and other code concerns
2004-07-07 opera -- frame injection vulnerability
png -- buffer overflow vulnerability on the row buffers
2004-06-20 pure-ftpd -- potential DoS when maximum connections is reached
2004-06-19 aspell -- buffer overflow in word-list-compress
2004-05-31 mailman -- member password disclosure vulnerability
2004-05-19 neon -- buffer overflow
cadaver -- buffer overflow in included libneon
2004-05-15 opera -- telnet URI handler file creation/truncation vulnerability
2004-05-10 exim -- buffer overflow when verify = header_syntax is used
2004-05-06 xonix -- failure to drop privileges
mplayer -- buffer overflow in Real RTSP streaming
lha -- buffer overflows and path traversal issues
2004-05-03 libpng -- out of bound access
2004-04-16 neon -- format string vulnerabilities
2004-04-15 mysql -- insecure temporary file creation
2004-04-14 cadaver -- format string vulnerabilities
2004-04-13 monit -- multiple vulnerabilities
2004-03-30 mplayer -- heap overflow in http requests
2004-03-03 squid -- ACL bypass due to URL decoding bug