OpenBSD VuXML

Documenting security issues in the OpenBSD Ports & Packages Collection

Security issues that affect the OpenBSD Ports & Packages Collection are documented using the Vulnerabilities and Exposures Markup Language (VuXML). The current VuXML document that serves as the source for the content of this site can be found:

topic index


Topic Entered
(X)emacs -- format string vulnerability 2005-02-09
acroread -- buffer overflow 2005-08-20
acroread -- mailListIsPdf() buffer overflow vulnerability 2004-12-22
aspell -- buffer overflow in word-list-compress 2004-06-19
bnc -- buffer overflow vulnerability 2004-11-10
bnc -- input validation flaw 2004-10-16
cabextract -- directory-traversal issue 2004-10-23
cadaver -- buffer overflow in included libneon 2004-05-19
cadaver -- format string vulnerabilities 2004-04-14
clamav -- denial of service vulnerability 2005-06-28
clamav -- heap overflow in the UPX code 2006-01-10
clamav -- multiple buffer overflows 2005-07-27
cups -- stack overflow in included xpdf code 2005-01-22
curl -- authentication buffer overflow vulnerability 2005-03-14
cyrus-sasl -- dynamic library loading and set-user-ID applications 2004-10-08
dante -- fd_set structure bitmap array index overflow 2005-01-31
enscript -- multiple vulnerabilities 2005-02-11
evolution -- arbitrary code execution vulnerability 2005-01-30
exim -- buffer overflow when verify = header_syntax is used 2004-05-10
exim -- two buffer overflow vulnerabilities 2005-01-26
fetchmail -- remote code injection vulnerability 2005-07-25
gaim -- DOS and buffer overflow vulnerabilities 2004-10-22
gaim -- multiple vulnerabilities 2005-04-07
gaim -- multiple vulnerabilities 2005-05-13
gaim -- remote execution of arbitrary code 2005-08-17
gcpio -- broken file permissions 2005-02-11
gnomevfs -- unsafe URI handling 2005-01-02
gnupg -- OpenPGP protocol attack 2005-03-27
gnutls -- denial of service vulnerability 2005-05-11
grip -- CDDB response multiple matches buffer overflow vulnerability 2005-03-22
icecast -- HTTP header overflow 2004-10-16
ImageMagick -- ReadPNMImage() heap overflow vulnerability 2005-05-01
imap-uw -- buffer verflow vulnerability 2005-10-07
imap-uw -- inappropriate user authentication (CRAM-MD5) 2005-01-29
jabberd -- buffer overflow vulnerabilities 2005-08-02
jabberd -- multiple vulnerabilities 2005-03-23
jftpgw -- format string vulnerability 2004-08-12
kdelibs -- konqueror cross-domain cookie injection 2004-08-25
leafnode -- denial of service vulnerability 2005-05-05
leafnode -- denial of service vulnerability 2005-06-09
lha -- buffer overflows and path traversal issues 2004-05-06
libexif -- buffer overflow vulnerability 2005-03-13
libpng -- out of bound access 2004-05-03
mailman -- cross-site scripting vulnerability 2005-01-26
mailman -- directory traversal vulnerability 2005-02-10
mailman -- member password disclosure vulnerability 2004-05-31
mc -- multiple vulnerabilities 2005-02-17
mlterm -- integer overflow vulnerability 2005-03-11
mod_auth_radius -- remote integer overflow 2005-01-24
monit -- multiple vulnerabilities 2004-04-13
mplayer -- buffer overflow in Real RTSP streaming 2004-05-06
mplayer -- heap overflow in http requests 2004-03-30
mplayer -- multiple overflow vulnerabilites 2004-12-22
mysql -- insecure temporary file creation 2004-04-15
mysql-server -- insecure file creation in mysqlhotcopy 2004-08-20
mysql-server -- mysqlaccess insecure temporary file creation 2005-01-19
nasm -- multiple vulnerabilities 2005-05-19
neon -- buffer overflow 2004-05-19
neon -- format string vulnerabilities 2004-04-16
net-snmp -- fixproc insecure temporary file creation 2005-05-25
openvpn -- several vulnerabilities 2005-08-23
opera -- Data URLs with executables and misleading download dialog 2005-02-05
opera -- frame injection vulnerability 2004-07-07
opera -- multiple vulnerabilities 2005-07-28
opera -- multiple vulnerabilities 2004-12-18
opera -- telnet URI handler file creation/truncation vulnerability 2004-05-15
p5-Convert-UUlib -- buffer overflow 2005-04-27
p5-Mail-SpamAssassin -- denial of service vulnerability 2005-07-10
pcre -- heap overflow 2005-08-22
php4 -- memory_limit remote vulnerability 2004-07-15
php4 -- multiple vulnerabilities 2004-12-18
php4 -- multiple vulnerabilities 2005-04-04
php4-pear -- PHP script injection vulnerability 2005-07-12
php5 -- multiple vulnerabilities 2004-12-20
php5 -- multiple vulnerabilities 2005-04-04
png -- buffer overflow vulnerability on the row buffers 2004-07-07
png -- stack-based buffer overflow and other code concerns 2004-08-04
postgresql -- privilege escalation via LOAD 2005-02-05
pure-ftpd -- potential DoS when maximum connections is reached 2004-06-20
rsnapshot -- local privilege escalation 2005-04-11
rsync -- path-sanitizing bug that affects daemon mode if chroot is disabled 2004-08-14
ruby -- arbitrary command execution on XMLRPC server 2005-07-01
ruby -- insecure file permissions 2004-08-17
samba -- potential buffer overrun with 'mangling method = hash' 2004-07-23
sox -- buffer overflows while handling malicious WAV files 2004-07-31
squid -- ACL bypass due to URL decoding bug 2004-03-03
squid -- multiple vulnerabilities 2005-05-25
squid -- several vulnerabilites 2005-01-26
squid -- SNMP related denial of service 2004-10-20
sylpheed -- message reply buffer overflow vulnerability 2005-04-04
tetex -- buffer overflow vunerability in included xpdf 2004-12-25
tiff -- multiple vulnerabilities 2005-03-27
tor -- critical security bug 2005-08-09
tor -- information disclosure vunlerability 2005-06-22
tor -- server disregards exit policies 2005-07-02
unace -- multiple buffer overflows 2005-02-22
unrtf -- buffer overflow vulnerability 2005-01-17
vim -- modelines execute arbitrary shell code 2005-07-27
xonix -- failure to drop privileges 2004-05-06
xpdf -- buffer overflow vunerability 2004-12-22
xpdf -- integer overflow vulnerabilities 2004-10-23
xpdf -- multiple stack overflows in makeFileKey2(); 2005-01-19
xv -- filename handling vulnerability 2005-03-15
xv -- multiple buffer overflows 2005-04-12
zip -- long path buffer overflow 2004-12-04