BSD

FreeBSD 15 — py38-treq — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — py38-treq — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-treq — sensitive information leak vulnerability Related CVEs: CVE-2022-23607 Upstream summary: Treq's request methods (`treq.get`, `treq.post`, `HTTPClient.request`, `HTTPClient.get`, etc.) accept cookies as a dictionary. Such cookies are not bound to […]

Read more
FreeBSD 14 — py38-Jinja — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py38-Jinja — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Jinja2 — Sandbox breakout through attr filter selecting format method Related CVEs: CVE-2024-34064 CVE-2025-27516 Upstream summary: [email protected] reports: Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in […]

Read more
FreeBSD 15 — rabbitmq-c-devel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — rabbitmq-c-devel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: RabbitMQ-C — integer overflow leads to heap corruption Related CVEs: CVE-2019-18609 Upstream summary: alanxz reports: When parsing a frame header, validate that the frame_size is less than or equal to […]

Read more
FreeBSD 15 — gzip — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — gzip — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zgrep — arbitrary file write Related CVEs: CVE-2005-0988 CVE-2005-1228 CVE-2006-4334 CVE-2006-4335 CVE-2006-4336 CVE-2006-4337 CVE-2006-4338 CVE-2022-1271 Upstream summary: RedHat reports: An arbitrary file write vulnerability was found in GNU gzip's zgrep […]

Read more
FreeBSD 14 — qt6-webengine — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — qt6-webengine — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 January 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: qt6-webengine — multiple vulnerabilities Related CVEs: CVE-2023-5186 CVE-2023-5187 CVE-2023-5217 CVE-2023-5218 CVE-2023-5473 CVE-2023-5474 CVE-2023-5475 CVE-2023-5476  +12 more Upstream summary: Qt qtwebengine-chromium repo reports: Backports for 262 security bugs in Chromium: CVE-2025-13223: […]

Read more
FreeBSD 15 — readstat — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — readstat — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: readstat — Heap buffer overflow in readstat_convert Upstream summary: Google reports: A heap buffer overflow exists in readstat_convert. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
FreeBSD 15 — ghostscript7-x — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — ghostscript7-x — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — exploitable buffer overflow in (T)BCP in PS interpreter Related CVEs: CVE-2015-3228 CVE-2023-28879 Upstream summary: [email protected] reports: In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to […]

Read more
NetBSD 10.0 — qt6-qtbase — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — qt6-qtbase — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2025-5991 CVE-2025-5455 CVE-2025-5992 Upstream summary: pkgsrc audit-packages flagged qt6-qtbase>=6.9.0<6.9.1 for vulnerability class 'use-after-free'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-5991 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
FreeBSD 13 — py313-ormar — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py313-ormar — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 January 2026 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-ormar — vulnerabilities Related CVEs: CVE-2026-26198 CVE-2026-27953 Upstream summary: https://github.com/ormar-orm/ormar/security/advisories reports: SQL Injection in aggregate functions min() and max() Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model […]

Read more
FreeBSD 15 — xrdb — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — xrdb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xrdb — root hole via rogue hostname Related CVEs: CVE-2011-0465 Upstream summary: Matthias Hopf reports: By crafting hostnames with shell escape characters, arbitrary commands can be executed in a root […]

Read more
CHAT