FreeBSD 15

FreeBSD 15 — horde-imp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — horde-imp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: horde-imp — XSS vulnerability Upstream summary: The Horde team reports: Thanks to Naumann IT Security Consulting for reporting the XSS vulnerability. The major changes compared to IMP version H3 (4.3.7) […]

Read more
FreeBSD 15 — wavpack — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — wavpack — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wavpack — integer overflow in pack_utils.c Related CVEs: CVE-2016-10169 CVE-2016-10170 CVE-2016-10171 CVE-2016-10172 CVE-2018-10536 CVE-2018-10537 CVE-2018-10538 CVE-2018-10539  +5 more Upstream summary: The wavpack project reports: src/pack_utils.c – issue #91: fix integer […]

Read more
FreeBSD 15 — lshell — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — lshell — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lshell — Shell autocomplete reveals forbidden directories Upstream summary: lshell reports: The autocomplete feature allows users to list directories, while they do not have access to those paths (issue #109). […]

Read more
FreeBSD 15 — zh-xemacs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — zh-xemacs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: emacs — movemail format string vulnerability Related CVEs: CVE-2005-0100 Upstream summary: Max Vozeler discovered several format string vulnerabilities in the movemail utility of Emacs. They can be exploited when connecting […]

Read more
FreeBSD 15 — p5-Crypt-OpenPGP — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — p5-Crypt-OpenPGP — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnupg — OpenPGP symmetric encryption vulnerability Related CVEs: CVE-2005-0366 Upstream summary: Serge Mister and Robert Zuccherato reports that the OpenPGP protocol is vulnerable to a cryptographic attack when using symmetric […]

Read more
FreeBSD 15 — podman — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — podman — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: podman — TLS connection used to pull VM images was not validated Related CVEs: CVE-2025-6032 Upstream summary: RedHat, Inc. reports: A flaw was found in Podman. The podman machine init […]

Read more
FreeBSD 15 — py37-notebook — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — py37-notebook — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: jupyter notebook — open redirect vulnerability Related CVEs: CVE-2019-10255 Upstream summary: Jupyter reports: 6.1.5 is a security release, fixing one vulnerability: Fix open redirect vulnerability GHSA-c7vm-f5p4-8fqh (CVE to be assigned) […]

Read more
FreeBSD 15 — lasso — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — lasso — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lasso — signature checking failure Related CVEs: CVE-2021-28091 Upstream summary: entrouvert reports: When AuthnResponse messages are not signed (which is permitted by the specifiation), all assertion's signatures should be checked, […]

Read more
FreeBSD 15 — php81-composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — php81-composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Composer — Multiple command injections via malicious git/hg branch names Related CVEs: CVE-2022-24828 CVE-2023-43655 CVE-2024-24821 CVE-2024-35241 CVE-2024-35242 Upstream summary: Composer project reports: The status, reinstall and remove commands with packages […]

Read more
FreeBSD 15 — llpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — llpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mupdf — multiple vulnerabilities Related CVEs: CVE-2016-6265 CVE-2016-6525 Upstream summary: Tobias Kortkamp reports: Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a […]

Read more
CHAT