[Git][security-tracker-team/security-tracker][master] grpc fixed in experimental
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 10 19:44:54 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0716f884 by Moritz Muehlenhoff at 2026-08-10T20:44:40+02:00
grpc fixed in experimental
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -271183,6 +271183,7 @@ CVE-2024-11669 (An issue was discovered in GitLab CE/EE affecting all versions f
CVE-2024-11668 (An issue has been discovered in GitLab CE/EE affecting all versions fr ...)
- gitlab <not-affected> (Vulnerable code introduced later)
CVE-2024-11407 (There exists a denial of service through Data corruption in gRPC-C++ - ...)
+ [experimental] - grpc 1.83.0-1
- grpc <unfixed> (bug #1088806)
[trixie] - grpc <not-affected> (vulnerable code introduced later)
[bookworm] - grpc <not-affected> (vulnerable code introduced later)
@@ -301187,6 +301188,7 @@ CVE-2024-7502 (A crafted DPA file could force Delta Electronics DIAScreen to ove
CVE-2024-7317 (The Folders \u2013 Unlimited Folders to Organize Media Library Folder, ...)
NOT-FOR-US: WordPress plugin
CVE-2024-7246 (It's possible for a gRPC client communicating with a HTTP/2 proxy to p ...)
+ [experimental] - grpc 1.83.0-1
- grpc <unfixed> (bug #1082856)
[trixie] - grpc <no-dsa> (Minor issue)
[bookworm] - grpc <no-dsa> (Minor issue)
@@ -378724,6 +378726,7 @@ CVE-2023-44487 (The HTTP/2 protocol allows a denial of service (server resource
- tomcat9 9.0.70-2
- tomcat10 10.1.14-1
- trafficserver 9.2.3+ds-1 (bug #1053801; bug #1054427)
+ [experimental] - grpc 1.83.0-1
- grpc <unfixed> (bug #1074421)
[trixie] - grpc <no-dsa> (Minor issue)
[bookworm] - grpc <no-dsa> (Minor issue)
@@ -382592,6 +382595,7 @@ CVE-2023-4802 (A reflected cross-site scripting vulnerability in the UpdateInsta
CVE-2023-4801 (An improper certification validation vulnerability in the Insider Thre ...)
NOT-FOR-US: Insider Threat Management (ITM) Server
CVE-2023-4785 (Lack of error handling in the TCP server in Google's gRPC starting ver ...)
+ [experimental] - grpc 1.83.0-1
- grpc <unfixed> (bug #1059281)
[trixie] - grpc <no-dsa> (Minor issue)
[bookworm] - grpc <no-dsa> (Minor issue)
@@ -387588,6 +387592,7 @@ CVE-2023-37068 (Code-Projects Gym Management System V1.0 allows remote attackers
CVE-2023-34545 (A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers ...)
NOT-FOR-US: CSZCMS
CVE-2023-33953 (gRPC contains a vulnerability that allows hpack table accounting error ...)
+ [experimental] - grpc 1.83.0-1
- grpc <unfixed> (bug #1059279)
[trixie] - grpc <no-dsa> (Minor issue)
[bookworm] - grpc <no-dsa> (Minor issue)
@@ -395357,6 +395362,7 @@ CVE-2023-34100 (Contiki-NG is an open-source, cross-platform operating system fo
CVE-2023-33557 (Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerabilit ...)
NOT-FOR-US: Fuel CMS
CVE-2023-32732 (gRPC contains a vulnerability whereby a client can cause a termination ...)
+ [experimental] - grpc 1.83.0-1
- grpc <unfixed> (bug #1059280)
[trixie] - grpc <no-dsa> (Minor issue)
[bookworm] - grpc <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0716f8843374e842ce712e6bfa127f57136c5f6e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0716f8843374e842ce712e6bfa127f57136c5f6e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/1edad791/attachment.htm>
More information about the debian-security-tracker-commits
mailing list