FreeBSD

FreeBSD 14 — py311-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py311-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-tflite — buffer overflow vulnerability Related CVEs: CVE-2021-37689 CVE-2022-41894 Upstream summary: Thibaut Goetghebuer-Planchon reports: The reference kernel of the CONV_3D_TRANSPOSE TensorFlow Lite operator wrongly increments the data_ptr when adding the […]

Read more
FreeBSD 13 — qt5-networkauth — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — qt5-networkauth — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: QtNetworkAuth — predictable seeding of PRNG in QAbstractOAuth Related CVEs: CVE-2024-36048 Upstream summary: Andy Shaw reports: The OAuth1 implementation in QtNetworkAuth created nonces using a PRNG that was seeded with […]

Read more
FreeBSD 14 — amavisd-new — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — amavisd-new — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: amavisd-new — multipart boundary confusion Related CVEs: CVE-2024-28054 Upstream summary: The Amavis project reports: Emails which consist of multiple parts (`Content-Type: multipart/*`) incorporate boundary information stating at which point one […]

Read more
FreeBSD 14 — weechat-devel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — weechat-devel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: weechat — Arbitrary shell command execution via scripts Related CVEs: CVE-2012-5854 Upstream summary: Sebastien Helleu reports: Untrusted command for function hook_process could lead to execution of commands, because of shell […]

Read more
FreeBSD 14 — zenphoto — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — zenphoto — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zenphoto — multiple vulnerabilities Related CVEs: CVE-2007-6666 CVE-2015-5591 CVE-2015-5592 CVE-2015-5593 CVE-2015-5594 CVE-2015-5595 Upstream summary: zenphoto reports: Fixes several SQL Injection, XSS and path traversal security issues Table of contents Symptom […]

Read more
FreeBSD 14 — kamailio — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — kamailio — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kamailio – buffer overflow Related CVEs: CVE-2016-2385 CVE-2018-8828 Upstream summary: A specially crafted REGISTER message with a malformed branch or From tag triggers an off-by-one heap-based buffer overflow in the […]

Read more
FreeBSD 14 — py32-graphite-web — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py32-graphite-web — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-graphite-web — Multiple vulnerabilities Related CVEs: CVE-2013-5093 Upstream summary: Graphite developers report: This release contains several security fixes for cross-site scripting (XSS) as well as a fix for a remote-execution […]

Read more
FreeBSD 14 — xlockmore — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — xlockmore — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xlockmore — local exploit Related CVEs: CVE-2012-4524 Upstream summary: Ignatios Souvatzis of NetBSD reports: Due to an error in the dclock screensaver in xlockmore, users who explicitly use this screensaver […]

Read more
FreeBSD 14 — pt_BR-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pt_BR-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2004-0752 CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading […]

Read more
FreeBSD 12 — oauth2-proxy — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — oauth2-proxy — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 April 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: oauth2-proxy — multiple vulnerabilities Related CVEs: CVE-2024-24784 CVE-2024-24786 CVE-2024-24790 CVE-2024-24791 CVE-2024-28180 CVE-2024-45288 CVE-2024-45338 CVE-2025-47914  +4 more Upstream summary: During session resumption in crypto/tls, if the underlying Config has its ClientCAs […]

Read more
CHAT