| /src/crypto/openssl/ |
| H A D | NEWS.md | 28 OpenSSL 3.5.5 is a security patch release. The most severe CVE fixed in this 34 ([CVE-2025-11187]) 37 ([CVE-2025-15467]) 40 ([CVE-2025-15468]) 43 ([CVE-2025-15469]) 46 ([CVE-2025-66199]) 49 ([CVE-2025-68160]) 53 ([CVE-2025-69418]) 56 ([CVE-2025-69419]) 60 ([CVE-2025-69420]) [all …]
|
| H A D | CHANGES.md | 49 ([CVE-2025-11187]) 65 ([CVE-2025-15467]) 82 ([CVE-2025-15468]) 101 ([CVE-2025-15469]) 120 ([CVE-2025-66199]) 139 ([CVE-2025-68160]) 159 ([CVE-2025-69418]) 177 ([CVE-2025-69419]) 196 ([CVE-2025-69420]) 212 ([CVE-2025-69421]) [all …]
|
| /src/contrib/tcpdump/ |
| H A D | CHANGES | 117 Use the buffer stack for de-escaping PPP; fixes CVE-2024-2397; 206 CVE-2023-1801: Fix an out-of-bounds write in the SMB printer. 393 CVE-2018-16301: For the -F option handle large input files safely. 465 CVE-2017-16808 (AoE) 466 CVE-2018-14468 (FrameRelay) 467 CVE-2018-14469 (IKEv1) 468 CVE-2018-14470 (BABEL) 469 CVE-2018-14466 (AFS/RX) 470 CVE-2018-14461 (LDP) 471 CVE-2018-14462 (ICMP) [all …]
|
| /src/crypto/heimdal/appl/rcp/ |
| H A D | ChangeLog | 18 Meissner at SUSE. Either of CVE-2006-3083 or CVE-2006-3084. 22 Meissner at SUSE. Either of CVE-2006-3083 or CVE-2006-3084. 26 Meissner at SUSE. Either of CVE-2006-3083 or CVE-2006-3084.
|
| /src/contrib/expat/ |
| H A D | Changes | 48 CVE-2025-59375 from #1034 (of Expat 2.7.2 and related 52 CVE-2024-8176 fix pull request #973 (of Expat 2.7.0 and 99 #1018 #1034 CVE-2025-59375 -- Disallow use of disproportional amounts of 174 (that the fix to CVE-2024-8176 changed in 2.7.0); 211 #893 #973 CVE-2024-8176 -- Fix crash from chaining a large number 283 #915 CVE-2024-50602 -- Fix crash within function XML_ResumeParser 295 #317 #918 tests: Improve tests on doctype closing (ex CVE-2019-15903) 316 #887 #890 CVE-2024-45490 -- Calling function XML_ParseBuffer with 325 #888 #891 CVE-2024-45491 -- Internal function dtdCopy can have an 330 #889 #892 CVE-2024-45492 -- Internal function nextScaffoldPart can [all …]
|
| /src/tests/sys/netpfil/pf/ |
| H A D | Makefile | 80 CVE-2019-5597.py \ 81 CVE-2019-5598.py \
|
| H A D | icmp.sh | 62 $(atf_get_srcdir)/CVE-2019-5598.py \
|
| H A D | fragmentation_compat.sh | 143 $(atf_get_srcdir)/CVE-2019-5597.py \
|
| H A D | fragmentation_pass.sh | 147 $(atf_get_srcdir)/CVE-2019-5597.py \
|
| /src/tools/build/options/ |
| H A D | WITHOUT_KERNEL_RETPOLINE | 1 Disable the "retpoline" mitigation for CVE-2017-5715 in the kernel
|
| H A D | WITH_KERNEL_RETPOLINE | 1 Enable the "retpoline" mitigation for CVE-2017-5715 in the kernel
|
| H A D | WITH_RETPOLINE | 2 vulnerability mitigation for CVE-2017-5715.
|
| /src/contrib/ntp/ |
| H A D | NEWS | 570 References: Sec 3454 / CVE-2018-7185 / VU#961909 608 References: Sec 3453 / CVE-2018-7184 / VU#961909 638 References: Sec 3415 / CVE-2018-7170 / VU#961909 639 Sec 3012 / CVE-2016-1549 / VU#718152 677 References: Sec 3414 / CVE-2018-7183 / VU#961909 701 References: Sec 3412 / CVE-2018-7182 / VU#961909 725 References: Sec 3012 / CVE-2016-1549 / VU#718152 893 References: Sec 3389 / CVE-2017-6464 / VU#325339 913 References: Sec 3388 / CVE-2017-6462 / VU#325339 937 References: Sec 3387 / CVE-2017-6463 / VU#325339 [all …]
|
| /src/contrib/file/tests/ |
| H A D | Makefile.am | 26 CVE-2014-1943.result \ 27 CVE-2014-1943.testfile \
|
| H A D | Makefile.in | 320 CVE-2014-1943.result \ 321 CVE-2014-1943.testfile \
|
| /src/contrib/bzip2/ |
| H A D | CHANGES | 324 * Security fix for CVE-2010-0405. This was reported by Mikolaj 338 * bzip2recover: Fix use after free issue with outFile (CVE-2016-3189) 340 * Make sure nSelectors is not out of range (CVE-2019-12900) 346 This relaxes the fix for CVE-2019-12900 from 1.0.7
|
| /src/contrib/xz/ |
| H A D | AUTHORS | 34 the team behind him inserted a backdoor (CVE-2024-3094) into
|
| /src/contrib/wpa/hostapd/ |
| H A D | ChangeLog | 34 (a mitigation for CVE-2023-52424; disabled by default for now, can be 122 [https://w1.fi/security/2019-1/] (CVE-2019-9494) 124 [https://w1.fi/security/2019-3/] (CVE-2019-9496) 127 [https://w1.fi/security/2019-2/] (CVE-2019-9495) 129 [https://w1.fi/security/2019-4/] (CVE-2019-9497 and CVE-2019-9498) 165 [http://w1.fi/security/2017-1/] (CVE-2017-13082) 219 [http://w1.fi/security/2015-7/] (CVE-2015-5314) 221 [http://w1.fi/security/2016-1/] (CVE-2016-4476) 292 [http://w1.fi/security/2015-2/] (CVE-2015-4141) 294 [http://w1.fi/security/2015-3/] (CVE-2015-4142) [all …]
|
| /src/crypto/openssl/test/recipes/30-test_evp_data/ |
| H A D | evpencod.txt | 138 # CVE 2015-0292
|
| /src/contrib/unbound/contrib/ |
| H A D | unbound.spec_fedora | 213 - removed integrated CVE patch 223 - Applied patch for CVE-2011-1922 DoS vulnerability 341 - Added dependency on minimum SSL for CVE-2008-5077
|
| /src/contrib/wpa/wpa_supplicant/ |
| H A D | ChangeLog | 46 (a mitigation for CVE-2023-52424; disabled by default for now, can be 152 [https://w1.fi/security/2019-1/] (CVE-2019-9494) 155 [https://w1.fi/security/2019-2/] (CVE-2019-9495) 157 [https://w1.fi/security/2019-4/] (CVE-2019-9499) 207 [https://w1.fi/security/2017-1/] (CVE-2017-13077, CVE-2017-13078, 208 CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, 209 CVE-2017-13086, CVE-2017-13087, CVE-2017-13088) 211 [https://w1.fi/security/2018-1/] (CVE-2018-14526) 276 [http://w1.fi/security/2015-6/] (CVE-2015-5310) 278 [http://w1.fi/security/2015-7/] (CVE-2015-5315) [all …]
|
| /src/sys/contrib/openzfs/tests/zfs-tests/tests/functional/crypto/ |
| H A D | aes_ccm_test.txt | 5462 flags: CVE-2017-18330 InvalidNonceSize 5473 flags: CVE-2017-18330 InvalidNonceSize 5484 flags: CVE-2017-18330 InvalidNonceSize 5605 flags: CVE-2017-18330 InvalidNonceSize 5616 flags: CVE-2017-18330 InvalidNonceSize 5627 flags: CVE-2017-18330 InvalidNonceSize 5748 flags: CVE-2017-18330 InvalidNonceSize 5759 flags: CVE-2017-18330 InvalidNonceSize 5770 flags: CVE-2017-18330 InvalidNonceSize
|
| /src/contrib/libpcap/ |
| H A D | CHANGES | 10 CVE-2025-11961: Fix OOBR and OOBW in pcap_ether_aton(). 78 CVE-2025-11964: Fix a bug in error message character encoding mapping 196 CVE-2023-7256: Clean up sock_initaddress() and its callers to avoid 200 CVE-2024-8006: Fix pcap_findalldevs_ex() not to crash if passed a 784 Five CVE-2019-15161, CVE-2019-15162, CVE-2019-15163, CVE-2019-15164, CVE-2019-15165
|
| /src/contrib/openpam/ |
| H A D | HISTORY | 81 result in a fail-open scenario. (CVE-2014-3879) 190 the policy file and some function arguments. (CVE-2011-4122)
|
| /src/crypto/openssl/doc/man3/ |
| H A D | SSL_CTX_set_options.pod | 410 CVE-2009-3555 and elsewhere. 448 CVE-2009-3555.
|