pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/doc
Module Name: pkgsrc
Committed By: wiz
Date: Fri Aug 28 08:10:50 UTC 2026
Modified Files:
pkgsrc/doc: pkg-vulnerabilities
Log Message:
doc: fix incorrect patterns for PKGNAME
>From audit by Showta Ishizaki in PR 60609.
(Patch applied and unnecessary lines removed.)
To generate a diff of this commit:
cvs rdiff -u -r1.782 -r1.783 pkgsrc/doc/pkg-vulnerabilities
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/doc/pkg-vulnerabilities
diff -u pkgsrc/doc/pkg-vulnerabilities:1.782 pkgsrc/doc/pkg-vulnerabilities:1.783
--- pkgsrc/doc/pkg-vulnerabilities:1.782 Fri Aug 28 07:58:26 2026
+++ pkgsrc/doc/pkg-vulnerabilities Fri Aug 28 08:10:50 2026
@@ -1,4 +1,4 @@
-# $NetBSD: pkg-vulnerabilities,v 1.782 2026/08/28 07:58:26 wiz Exp $
+# $NetBSD: pkg-vulnerabilities,v 1.783 2026/08/28 08:10:50 wiz Exp $
#
#FORMAT 1.0.0
#
@@ -24998,16 +24998,16 @@ alpine<2.25 denial-of-service https://nv
amanda-client<3.3.9nb7 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2022-37703
GraphicsMagick<1.3.38 heap-based-buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2022-1270
ap{22,24}-auth-openidc<2.4.12.2 open-redirect https://nvd.nist.gov/vuln/detail/CVE-2022-23527
-postgresql-server>=10<10.22 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=11<11.17 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=12<12.12 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=13<13.8 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=14<14.5 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
-postgresql-server>=10<10.21 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=11<11.16 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=12<12.11 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=13<13.7 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
-postgresql-server>=14<14.3 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql10-server<10.22 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql11-server<11.17 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql12-server<12.12 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql13-server<13.8 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql14-server<14.5 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-2625
+postgresql10-server<10.21 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql11-server<11.16 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql12-server<12.11 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql13-server<13.7 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
+postgresql14-server<14.3 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2022-1552
asterisk>=16<16.16.2 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-46837
asterisk>=17<17.9.3 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-46837
asterisk>=18<18.2.2 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-46837
@@ -25086,7 +25086,7 @@ nodejs>=18<18.14.1 security-restrictions
nodejs>=19<19.6.1 security-restrictions-bypass https://nvd.nist.gov/vuln/detail/CVE-2023-23918
apache<2.4.56 http-response-splitting https://nvd.nist.gov/vuln/detail/CVE-2023-27522
apache<2.4.56 http-response-splitting https://nvd.nist.gov/vuln/detail/CVE-2023-25690
-yubico-c-client-[0-9]* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+ykclient-[0-9]* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
curl>=7.7<8.00 command-injection https://nvd.nist.gov/vuln/detail/CVE-2023-27533
curl>=7.18<8.00 improper-path-limitation https://nvd.nist.gov/vuln/detail/CVE-2023-27534
curl>=7.13<8.00 authentication-bypass https://nvd.nist.gov/vuln/detail/CVE-2023-27535
@@ -25473,8 +25473,8 @@ libxml2<2.12.2 use-after-free https://nv
libcue<2.2.1nb1 memory-corruption https://nvd.nist.gov/vuln/detail/CVE-2023-43641
mutt<2.2.12 null-pointer-dereference https://nvd.nist.gov/vuln/detail/CVE-2023-4874
mutt<2.2.12 null-pointer-dereference https://nvd.nist.gov/vuln/detail/CVE-2023-4875
-djvulibre-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-46312
-djvulibre-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-46310
+djvulibre-lib-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-46312
+djvulibre-lib-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2021-46310
grpc<1.53.0 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2023-32732
grpc>=1.53.0<1.55.0 expected-behavior-violation https://nvd.nist.gov/vuln/detail/CVE-2023-32731
grpc>=1.51.0<1.53.0 expected-behavior-violation https://nvd.nist.gov/vuln/detail/CVE-2023-1428
@@ -25726,7 +25726,7 @@ php{56,73,74,80,81,82}-roundcube<1.6.3 c
exiv2>=0.28<0.28.1 out-of-bounds-write https://nvd.nist.gov/vuln/detail/CVE-2023-44398
ltm<1.2.1 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-36328
gimp<2.10.36 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2023-44441
-qimp<2.10.36 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2023-44442
+gimp<2.10.36 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2023-44442
gimp<2.10.36 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2023-44443
gimp<2.10.36 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2023-44444
tor<0.4.8.8 unknown-impact https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE
@@ -25824,7 +25824,7 @@ modular-xorg-server<21.1.11 heap-buffer-
coreutils<9.4 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2024-0684
gnutls<3.8.3 timing-side-channel https://nvd.nist.gov/vuln/detail/CVE-2023-0553
py{27,38,39,310,311,312}-Pillow<10.2.0 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2023-50447
-postgresql-server>=11<12 eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+postgresql11-* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
nodejs>=16<18 eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
py{27,37,38,39,310,311,312}-aiohttp<3.9.2 directory-traversal https://nvd.nist.gov/vuln/detail/CVE-2024-23334
py{27,37,38,39,310,311,312}-aiohttp<3.9.2 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-23829
@@ -25845,11 +25845,11 @@ py{37,38,39,310,311,312}-django>=3.2<3.2
py{37,38,39,310,311,312}-django>=4.1<4.2 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-24680
py{37,38,39,310,311,312}-django>=4.2<4.2.10 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-24680
libuv>=1.24.0<1.48 address-check-bypass https://nvd.nist.gov/vuln/detail/CVE-2024-24806
-postgresql-server>=12<12.18 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=13<13.14 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=14<14.11 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=15<15.6 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
-postgresql-server>=16<16.2 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql12-server<12.18 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql13-server<13.14 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql14-server<14.11 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql15-server<15.6 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
+postgresql16-server<16.2 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2024-0985
asterisk-13.* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
unbound<1.19.1 denial-of-service https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50387
unbound<1.19.1 denial-of-service https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50868
@@ -25973,7 +25973,7 @@ asterisk>=21<21.3.1 authentication-bypas
keepassxc-[0-9]* sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2024-33900
keepassxc-[0-9]* sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2024-33901
py{27,37,38,39,310,311,312}-requests<2.32.0 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2024-35195
-py{37,38,39,310,311,312}-mysql<1.1.0 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-36039
+py{37,38,39,310,311,312}-pymysql<1.1.1 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2024-36039
gst-plugins1-base<1.24.3 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2024-4453
#lighttpd-[0-9]* sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2024-3708 # rejected, withdrawn by CNA
libarchive<3.7.4 out-of-bounds-access https://nvd.nist.gov/vuln/detail/CVE-2024-26256
@@ -26102,13 +26102,13 @@ openafs<1.6.25 denial-of-service http:/
openafs>=1.7<1.8.13 denial-of-service http://openafs.org/pages/security/OPENAFS-SA-2024-002.txt
openafs<1.6.25 buffer-overflow http://openafs.org/pages/security/OPENAFS-SA-2024-003.txt
openafs>=1.7<1.8.13 buffer-overflow http://openafs.org/pages/security/OPENAFS-SA-2024-003.txt
-postgresql-server>=12<13 eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+postgresql12-* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
wget<1.25.0 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2024-10524
webkit-gtk<2.46.4 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-44308
py{38,39,310,311,312}-django>=4<4.2.17 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-53907
py{38,39,310,311,312}-django>=5<5.1.4 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-53907
curl<8.11.1 credential-leak https://nvd.nist.gov/vuln/detail/CVE-2024-11053
-gstreamer-1.24.10 multiple-vulnerabilities https://discourse.gstreamer.org/t/gstreamer-1-24-10-stable-bug-fix-release/3683
+gstreamer1<1.24.10 multiple-vulnerabilities https://discourse.gstreamer.org/t/gstreamer-1-24-10-stable-bug-fix-release/3683
firefox<131.0.2 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-9680
firefox128<128.3.1 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-9680
firefox115<115.16.1 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-9680
@@ -26126,11 +26126,11 @@ drupal>=7<8 eol https://www.drupal.org/p
libtasn1<4.20.0 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-12133
openssl>=3.3<3.3.3 man-in-the-middle https://nvd.nist.gov/vuln/detail/CVE-2024-12797
openssl>=3.4<3.4.1 man-in-the-middle https://nvd.nist.gov/vuln/detail/CVE-2024-12797
-postgresql-server>=13<13.19 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=14<14.16 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=15<15.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=16<16.7 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
-postgresql-server>=17<17.3 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql13-server<13.19 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql14-server<14.16 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql15-server<15.11 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql16-server<16.7 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
+postgresql17-server<17.3 sql-injection https://nvd.nist.gov/vuln/detail/CVE-2025-1094
vim<9.1.1115 use-after-free https://github.com/vim/vim/security/advisories/GHSA-63p5-mwg2-787v
libxml2<2.12.10 stack-buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-24928
libxml2<2.12.10 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2024-56171
@@ -26184,11 +26184,11 @@ dnsdist<1.9.9 use-after-free https://nv
liboqs<0.13.0 information-disclosure https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/Wiu4ZQo3fP8
py{39,310,311,312,313}-django<4.2.21 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-32873
py{39,310,311,312,313}-django>=5<5.2.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-32873
-postgresql-server>=13<13.21 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=14<14.18 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=15<15.13 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=16<16.9 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
-postgresql-server>=17<17.5 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql13-server<13.21 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql14-server<14.18 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql15-server<15.13 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql16-server<16.9 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
+postgresql17-server<17.5 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-4207
dropbear<2025.88 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-47203
screen<4.9.1nb2 multiple-vulnerabilities https://security.opensuse.org/2025/05/12/screen-security-issues.html
screen>=5<5.0.0nb3 multiple-vulnerabilities https://security.opensuse.org/2025/05/12/screen-security-issues.html
@@ -27118,7 +27118,7 @@ apache<2.4.64 denial-of-service https:/
chromium<138.0.7204.96 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-6554
cpp-httplib<0.20.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-53628
cpp-httplib<0.20.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-53629
-djvulibre<3.5.29 out-of-bounds-read https://nvd.nist.gov/vuln/detail/CVE-2025-53367
+djvulibre-lib<3.5.29 out-of-bounds-read https://nvd.nist.gov/vuln/detail/CVE-2025-53367
dpkg<1.22.21 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-6297
gdk-pixbuf2<2.42.12nb3 out-of-bounds-read https://nvd.nist.gov/vuln/detail/CVE-2025-7345
git-base>=2.50<2.50.1 buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-48386
@@ -27132,7 +27132,6 @@ git-base>=2.43<2.43.7 buffer-overflow
gnutls<3.8.10 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-32989
gnutls<3.8.10 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-32990
gnutls<3.8.10 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-6395
-gstreamer<1.26.3 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-6663
gtar-[0-9]* directory-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-45582
guacamole-server<1.6.0 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2024-35164
hdf5-[0-9]* heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-7067
@@ -27392,21 +27391,21 @@ jetty<9.4.58 denial-of-service https:
libsixel<1.8.7 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-9300
libsndfile-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-52194
libssh<0.112 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-4877
-postgresql-server>=13<13.22 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=14<14.19 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=15<15.14 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=16<16.10 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=17<17.6 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
-postgresql-server>=13<13.22 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=14<14.19 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=15<15.14 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=16<16.10 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=17<17.6 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
-postgresql-server>=13<13.22 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=14<14.19 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=15<15.14 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=16<16.10 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
-postgresql-server>=17<17.6 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql13-server<13.22 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql14-server<14.19 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql15-server<15.14 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql16-server<16.10 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql17-server<17.6 information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-8713
+postgresql13-server<13.22 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql14-server<14.19 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql15-server<15.14 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql16-server<16.10 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql17-server<17.6 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8714
+postgresql13-server<13.22 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql14-server<14.19 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql15-server<15.14 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql16-server<16.10 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
+postgresql17-server<17.6 code-injection https://nvd.nist.gov/vuln/detail/CVE-2025-8715
proftpd<1.3.3d backdoor https://nvd.nist.gov/vuln/detail/CVE-2010-20103
# disputed, this is how Python's import works
#py{27,39,310,311,312,313}-future-[0-9]* arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-50817
@@ -28040,7 +28039,7 @@ botan<2.19.5 improper-certificate-valida
botan>=3<3.5.0 improper-certificate-validation https://nvd.nist.gov/vuln/detail/CVE-2024-39312
botan<3.6.0 unspecified https://nvd.nist.gov/vuln/detail/CVE-2024-50382
botan<3.6.0 unspecified https://nvd.nist.gov/vuln/detail/CVE-2024-50383
-c-ares<1.17.0 buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-22217
+libcares<1.17.1 buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2020-22217
cJSON<1.7.17 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2023-50471
cJSON<1.7.17 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2023-50472
cJSON<1.7.18 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-31755
@@ -28092,7 +28091,7 @@ clamav<1.4.1 privilege-escalation https:
clamav<1.4.2 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-20128
clojure<1.9.0 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2017-20189
clojure<1.12.0 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-22871
-commonmarker<0.23.4 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2024-22051
+ruby{26,27,30,31,32,33,34}-commonmarker<0.23.4 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2024-22051
consul<1.20.1 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2024-10005
consul<1.20.1 security-bypass https://nvd.nist.gov/vuln/detail/CVE-2024-10006
consul<1.20.0 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2024-10086
@@ -28820,7 +28819,7 @@ gstreamer1<1.24.10 null-pointer-derefere
# Gstreamer Installer, not used by pkgsrc
#gstreamer1-[0-9]* privilege-escalation https://nvd.nist.gov/vuln/detail/CVE-2025-2759
gstreamer1<1.26.1 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-3887
-gstreamer1<1.222.4 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-37327
+gstreamer1<1.22.4 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-37327
gstreamer1<1.22.5 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-38103
gstreamer1<1.22.5 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-38104
gstreamer1<1.22.8 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-50186
@@ -28916,18 +28915,16 @@ php{56,74,81,82,83,84}-phppgadmin<9.10 r
php{56,74,81,82,83,84}-phppgadmin<9.10 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-12763
php{56,74,81,82,83,84}-phppgadmin<9.10 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12764
php{56,74,81,82,83,84}-phppgadmin<9.10 improper-certificate-validation https://nvd.nist.gov/vuln/detail/CVE-2025-12765
-postgresql-client<13.23 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=14<14.20 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=15<15.15 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=16<16.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=17<17.7 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-client>=18<18.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
-postgresql-server<13.23 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=14<14.20 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=15<15.15 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=16<16.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=17<17.7 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
-postgresql-server>=18<18.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql14-client<14.20 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql15-client<15.15 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql16-client<16.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql17-client<17.7 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql18-client<18.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql14-server<14.20 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql15-server<15.15 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql16-server<16.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql17-server<17.7 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql18-server<18.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
radare2<6.0.5 null-pointer-dereference https://nvd.nist.gov/vuln/detail/CVE-2025-63744
radare2<6.0.5 null-pointer-dereference https://nvd.nist.gov/vuln/detail/CVE-2025-63745
qjson-[0-9]* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
@@ -29326,7 +29323,7 @@ iperf3<3.15 denial-of-service https://nv
iperf3<3.14 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2023-38403
iperf3<3.17 timing-side-channel https://nvd.nist.gov/vuln/detail/CVE-2024-26306
iperf3<3.18 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2024-53580
-php-8.1<8.2 eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
+php>=8.1<8.2 eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
php81-* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
chromium<143.0.7499.192 code-injection https://nvd.nist.gov/vuln/detail/CVE-2026-0628
libtasn1<4.21.0 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-13151
@@ -29906,32 +29903,23 @@ p5-Image-ExifTool<13.50 command-injectio
php{56,74,81,82,83,84}-owncloud-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2019-25337
php{56,74,81,82,83,84}-piwigo<15.0.0 insufficiently-random-numbers https://nvd.nist.gov/vuln/detail/CVE-2024-48928
php{56,74,81,82,83,84}-piwigo-[0-9]* information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2025-62512
-postgresql-server<14.21 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=15<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=16<16.12 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=17<17.8 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server>=18<18.2 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
-postgresql-server<14.21 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=15<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=16<16.12 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=17<17.8 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server>=18<18.2 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
-postgresql-server<14.21 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=15<15.16 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=16<16.12 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=17<17.8 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=17<17.8 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server>=18<18.2 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
-postgresql-server<14.21 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=15<15.16 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=16<16.12 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=17<17.8 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=18<18.2 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
-postgresql-server>=18<18.2 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2007
+postgresql15-server<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql16-server<16.12 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql17-server<17.8 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql18-server<18.2 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql15-server<15.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql16-server<16.12 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql17-server<17.8 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql18-server<18.2 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql15-server<15.16 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql16-server<16.12 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql17-server<17.8 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql18-server<18.2 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql15-server<15.16 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql16-server<16.12 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql17-server<17.8 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql18-server<18.2 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
+postgresql18-server<18.2 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2007
py{27,310,311,312,313,314}-Pillow<12.1.1 out-of-bounds-write https://nvd.nist.gov/vuln/detail/CVE-2026-25990
py{27,310,311,312,313,314}-flask<3.1.3 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2026-27205
py{27,310,311,312,313,314}-nltk<3.9.3 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2025-14009
@@ -30145,7 +30133,7 @@ libssh<0.11.4 out-of-bounds-read https:/
mold-[0-9]* heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-3994
openexr<3.4.6 out-of-bounds-write https://nvd.nist.gov/vuln/detail/CVE-2026-27622
openssl<3.6.2 security-bypass https://nvd.nist.gov/vuln/detail/CVE-2026-2673
-p5-Apache-Session-Generate-[0-9]* weak-cryptography https://nvd.nist.gov/vuln/detail/CVE-2025-40931
+p5-Apache-Session-[0-9]* weak-cryptography https://nvd.nist.gov/vuln/detail/CVE-2025-40931
php{56,74,81,82,83,84}-concrete-cms<9.4.8 cross-site-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2026-2994
php{56,74,81,82,83,84}-concrete-cms<9.4.8 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2026-3240
php{56,74,81,82,83,84}-concrete-cms<9.4.8 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2026-3241
@@ -30424,6 +30412,13 @@ nginx{,-devel}>=1.15.8<1.30.4 sensitive-
nginx{,-devel}>=1.31.0<1.31.3 sensitive-information-disclosure https://nvd.nist.gov/vuln/detail/CVE-2026-60005
nginx{,-devel}>=0.9.6<1.30.4 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-42533
nginx{,-devel}>=1.31.0<1.31.3 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-42533
+gst-plugins1-bad<1.26.3 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-6663
+postgresql13-client<13.23 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12818
+postgresql13-server<13.23 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-12817
+postgresql14-server<14.21 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2003
+postgresql14-server<14.21 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-2004
+postgresql14-server<14.21 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-2005
+postgresql14-server<14.21 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2026-2006
clamav<0.92 integer-overflow https://nvd.nist.gov/vuln/detail/CVE-2007-6335
echoping-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2010-5111
sqlite3>=3.49.0<3.49.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-29088
Home |
Main Index |
Thread Index |
Old Index