BSD

NetBSD 10.0 — libvpx — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — libvpx — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2010-4489 CVE-2019-9232 CVE-2019-9325 CVE-2023-5217 CVE-2025-5283 CVE-2017-13194 CVE-2019-9371 CVE-2019-9433 Upstream summary: pkgsrc audit-packages flagged libvpx<0.9.6 for vulnerability class 'remote-system-access'. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4489 Table of contents Symptom & Impact Environment & Reproduction […]

Read more
FreeBSD 13 — 7-zip — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — 7-zip — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 October 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: 7-Zip — Multi-byte write heap buffer overflow in NCompress::NRar5::CDecoder Related CVEs: CVE-2025-53816 Upstream summary: [email protected] reports: 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap […]

Read more
FreeBSD 13 — linux-c7-libxslt — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-c7-libxslt — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 October 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libxslt — multiple vulnerabilities Related CVEs: CVE-2025-11731 CVE-2025-7424 CVE-2025-7425 CVE-2025-9714 Upstream summary: Alan Coopersmith reports: On 6/16/25 15:12, Alan Coopersmith wrote: BTW, users of libxml2 may also be using its […]

Read more
FreeBSD 14 — py311-django — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py311-django — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 October 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Django — multiple vulnerabilities Related CVEs: CVE-2023-31047 CVE-2023-36053 CVE-2023-41164 CVE-2023-43665 CVE-2024-24680 CVE-2024-27351 CVE-2024-38875 CVE-2024-39329  +9 more Upstream summary: Django reports: CVE-2025-59681: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() […]

Read more
NetBSD 10.0 — py-test — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — py-test — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2025-71176 Upstream summary: pkgsrc audit-packages flagged py{27,310,311,312,313,314}-test-[0-9]* for vulnerability class 'insecure-temporary-files'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-71176 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
FreeBSD 12 — mod_http — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mod_http — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 October 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_http2 — Multiple vulnerabilities Related CVEs: CVE-2020-11984 CVE-2020-11993 CVE-2020-9490 CVE-2024-24795 CVE-2024-27316 CVE-2024-38709 CVE-2025-49630 CVE-2025-53020 Upstream summary: The mod_http2 project reports: a client can increase memory consumption for a HTTP/2 connection […]

Read more
FreeBSD 13 — py312-libxml — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py312-libxml — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 October 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libxml2 — Out-of-bounds memory access Related CVEs: CVE-2025-32414 Upstream summary: [email protected] reports: In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python […]

Read more
NetBSD 9.4 — lasso — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — lasso — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2025-47151 CVE-2021-28091 CVE-2025-46404 CVE-2025-46705 CVE-2025-46784 Upstream summary: pkgsrc audit-packages flagged lasso<2.9.0 for vulnerability class 'arbitrary-code-execution'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-47151 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
NetBSD 10.0 — libxslt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — libxslt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2008-1767 CVE-2019-18197 CVE-2021-30560 CVE-2025-24855 CVE-2025-10911 CVE-2016-1683 CVE-2016-1684 CVE-2015-9019  +12 more Upstream summary: pkgsrc audit-packages flagged libxslt<1.1.24 for vulnerability class 'remote-system-access'. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1767 Table of contents Symptom & Impact Environment […]

Read more
NetBSD 9.4 — postgresql-client — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — postgresql-client — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2025-12818 Upstream summary: pkgsrc audit-packages flagged postgresql-client<13.23 for vulnerability class 'denial-of-service'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-12818 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
CHAT