i already posted these to the 32.8 stable thread: http://cve.mitre.org/cve/cve.html and http://web.nvd.nist.gov/view/vuln/search . these are US government sponsored efforts to collect and catalog vulnerability information, for over a decade now. there're also other collections like bugtraq/vupen/secunia/etc but CVE is considered the etalon these days i think.