BSD

NetBSD 10.0 — mbedtls — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — mbedtls — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2017-2784 CVE-2018-0487 CVE-2018-0488 CVE-2025-47917 CVE-2017-14032 CVE-2018-1000520 CVE-2018-0497 CVE-2018-0498  +12 more Upstream summary: pkgsrc audit-packages flagged mbedtls<1.3.19 for vulnerability class 'remote-code-execution'. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-2784 Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 15 — py27-djblets — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — py27-djblets — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 March 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-djblets — Self-XSS vulnerability Upstream summary: Djblets Release Notes reports: A recently-discovered vulnerability in the datagrid templates allows an attacker to generate a URL to any datagrid page containing malicious […]

Read more
FreeBSD 15 — linux-f10-libgcrypt — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — linux-f10-libgcrypt — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 March 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GnuPG and Libgcrypt — side-channel attack vulnerability Related CVEs: CVE-2013-4242 Upstream summary: Werner Koch of the GNU project reports: Noteworthy changes in version 1.5.3: Mitigate the Yarom/Falkner flush+reload side-channel attack […]

Read more
NetBSD 10.0 — calibre — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — calibre — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2018-7889 CVE-2024-6782 CVE-2025-64486 CVE-2026-25731 CVE-2011-4126 CVE-2011-4124 CVE-2011-4125 CVE-2023-46303  +12 more Upstream summary: pkgsrc audit-packages flagged calibre<3.19.0 for vulnerability class 'arbitrary-code-execution'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2018-7889 Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 15 — dircproxy — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — dircproxy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 March 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dircproxy — remote denial of service Related CVEs: CVE-2007-5226 Upstream summary: Securiweb reports: dircproxy allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without […]

Read more
FreeBSD 15 — rubygem-doorkeeper-rails — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — rubygem-doorkeeper-rails — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 March 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-doorkeeper — token revocation vulnerability Related CVEs: CVE-2018-1000211 Upstream summary: NVD reports: Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that […]

Read more
FreeBSD 15 — py39-Jinja — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — py39-Jinja — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 March 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Jinja2 — Sandbox breakout through attr filter selecting format method Related CVEs: CVE-2024-34064 CVE-2025-27516 Upstream summary: [email protected] reports: Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in […]

Read more
NetBSD 10.0 — xenkernel420 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — xenkernel420 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2025-27466 CVE-2025-58142 CVE-2025-58143 CVE-2025-58149 CVE-2025-58150 CVE-2025-58147 CVE-2025-58148 CVE-2026-23553 Upstream summary: pkgsrc audit-packages flagged xenkernel420<20251113 for vulnerability class 'null-pointer-dereference'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-27466 Table of contents Symptom & Impact Environment & Reproduction […]

Read more
FreeBSD 15 — plexmediaserver — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — plexmediaserver — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 March 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Plex Media Server — security vulnerability Related CVEs: CVE-2018-13415 CVE-2021-42835 Upstream summary: Plex Security Team reports: We have recently been made aware of a security vulnerability in Plex Media Server […]

Read more
FreeBSD 15 — ko-hcode — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — ko-hcode — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 March 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: hcode — buffer overflow in mail.c Related CVEs: CVE-2024-34020 Upstream summary: The openSUSE project reports: The problematic function in question is putSDN() in mail.c. The static variable `cp` is used […]

Read more
CHAT