pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/doc
Module Name: pkgsrc
Committed By: leot
Date: Fri Oct 10 10:27:47 UTC 2025
Modified Files:
pkgsrc/doc: pkg-vulnerabilities
Log Message:
pkg-vulnerabilities: add (part of) old CVEs for PKGBASEs starting with "c"
+ c-ares, cJSON, cacti, calibre,
catdoc (probably not fixed and unclear if reported upstream),
cfengine,
cflow (not fixed)
To generate a diff of this commit:
cvs rdiff -u -r1.598 -r1.599 pkgsrc/doc/pkg-vulnerabilities
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/doc/pkg-vulnerabilities
diff -u pkgsrc/doc/pkg-vulnerabilities:1.598 pkgsrc/doc/pkg-vulnerabilities:1.599
--- pkgsrc/doc/pkg-vulnerabilities:1.598 Fri Oct 10 10:03:02 2025
+++ pkgsrc/doc/pkg-vulnerabilities Fri Oct 10 10:27:47 2025
@@ -1,4 +1,4 @@
-# $NetBSD: pkg-vulnerabilities,v 1.598 2025/10/10 10:03:02 leot Exp $
+# $NetBSD: pkg-vulnerabilities,v 1.599 2025/10/10 10:27:47 leot Exp $
#
#FORMAT 1.0.0
#
@@ -28031,3 +28031,45 @@ botan<2.19.5 improper-certificate-valida
botan>=3<3.5.0 improper-certificate-validation https://nvd.nist.gov/vuln/detail/CVE-2024-39312
botan<3.6.0 unspecified https://nvd.nist.gov/vuln/detail/CVE-2024-50382
botan<3.6.0 unspecified https://nvd.nist.gov/vuln/detail/CVE-2024-50383
+c-ares<1.17.0 buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-22217
+cJSON<1.7.17 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2023-50471
+cJSON<1.7.17 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2023-50472
+cJSON<1.7.18 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-31755
+cacti<1.2.26 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2023-46490
+cacti<1.2.26 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2023-49084
+cacti<1.2.26 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2023-49085
+cacti<1.2.27 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2023-49086
+cacti<1.2.26 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2023-49088
+cacti<1.2.26 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2023-50250
+cacti<1.2.26 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2023-51448
+cacti<1.2.27 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-25641
+cacti<1.2.27 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-27082
+cacti<1.2.27 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-29894
+cacti>=1.3<1.4 command-injection https://nvd.nist.gov/vuln/detail/CVE-2024-29895
+cacti>=1.3<1.4 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-30268
+cacti<1.2.27 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-31443
+cacti<1.2.27 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-31444
+cacti<1.2.27 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-31445
+cacti<1.2.27 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-31458
+cacti<1.2.27 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-31459
+cacti<1.2.27 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-31460
+cacti<1.2.27 authentication-bypass https://nvd.nist.gov/vuln/detail/CVE-2024-34340
+cacti<1.2.28 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-43362
+cacti<1.2.28 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-43363
+cacti<1.2.28 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-43364
+cacti<1.2.28 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-43365
+cacti<1.2.29 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2024-45598
+cacti<1.2.29 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-54145
+cacti<1.2.29 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-54146
+cacti<1.2.29 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-22604
+cacti<1.2.29 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-24367
+cacti<1.2.29 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-24368
+cacti<1.2.29 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-26520
+calibre<6.19.0 server-side-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2023-46303
+calibre<7.16.0 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2024-6781
+calibre<7.16.0 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-6782
+calibre<7.16.0 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-7008
+calibre<7.16.0 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-7009
+catdoc-[0-9]* null-pointer-dereference https://nvd.nist.gov/vuln/detail/CVE-2023-46345
+cfengine<3.21.3 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2023-45684
+cflow-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2023-2789
Home |
Main Index |
Thread Index |
Old Index