Skip to content

Commit 9c722f8

Browse files
committed
pkg-vulnerabilities: Add recent CVEs
+ bind, chromium, mysql-client, mysql-cluster, mysql-server, openjdk{11,17,21}, sqlite3, unbound, vim, xenkernel{415,418} (fixed via XSA-470 patch, no stable releases with patch)
1 parent 2e13e42 commit 9c722f8

1 file changed

Lines changed: 18 additions & 1 deletion

File tree

doc/pkg-vulnerabilities

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# $NetBSD: pkg-vulnerabilities,v 1.469 2025/07/16 21:44:36 wiz Exp $
1+
# $NetBSD: pkg-vulnerabilities,v 1.470 2025/07/17 09:38:19 leot Exp $
22
#
33
#FORMAT 1.0.0
44
#
@@ -27164,3 +27164,20 @@ py{27,39,310,311,312,313}-aiohttp<3.12.14 request-smuggling https://nvd.nist.gov
2716427164
roundup<2.5.0 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2025-53865
2716527165
p5-Plack-Middleware-Session<0.35 insufficiently-random-numbers https://nvd.nist.gov/vuln/detail/CVE-2025-40923
2716627166
p5-Authen-SASL<2.1800nb2 insufficiently-random-numbers https://nvd.nist.gov/vuln/detail/CVE-2025-40918
27167+
bind>=9.20<9.20.11 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-40777
27168+
chromium<138.0.7204.157 sandbox-escape https://nvd.nist.gov/vuln/detail/CVE-2025-6558
27169+
chromium<138.0.7204.157 heap-corruption https://nvd.nist.gov/vuln/detail/CVE-2025-7656
27170+
chromium<138.0.7204.157 heap-corruption https://nvd.nist.gov/vuln/detail/CVE-2025-7657
27171+
mysql-client<8.0.43 multiple-vulnerabilities https://www.oracle.com/security-alerts/cpujul2025.html#AppendixMSQL
27172+
mysql-cluster<8.0.43 multiple-vulnerabilities https://www.oracle.com/security-alerts/cpujul2025.html#AppendixMSQL
27173+
mysql-server<8.0.43 multiple-vulnerabilities https://www.oracle.com/security-alerts/cpujul2025.html#AppendixMSQL
27174+
openjdk11<11.0.28 multiple-vulnerabilities https://www.oracle.com/security-alerts/cpujul2025.html#AppendixJAVA
27175+
openjdk17<17.0.16 multiple-vulnerabilities https://www.oracle.com/security-alerts/cpujul2025.html#AppendixJAVA
27176+
openjdk21<21.0.8 multiple-vulnerabilities https://www.oracle.com/security-alerts/cpujul2025.html#AppendixJAVA
27177+
php{56,73,74,80,81,82,83,84}-tiki6<14.2 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-34113
27178+
sqlite3<3.50.2 memory-corruption https://nvd.nist.gov/vuln/detail/CVE-2025-6965
27179+
unbound<1.23.1 cache-poisoning https://nvd.nist.gov/vuln/detail/CVE-2025-5994
27180+
vim<9.1.1552 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-53905
27181+
vim<9.1.1551 path-traversal https://nvd.nist.gov/vuln/detail/CVE-2025-53906
27182+
xenkernel415-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-27465
27183+
xenkernel418-[0-9]* denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-27465

0 commit comments

Comments
 (0)