[Git][security-tracker-team/security-tracker][master] Associate some older Cloudflare Quiche issues with itp'ed entry
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jul 25 06:59:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7a916f5c by Salvatore Bonaccorso at 2026-07-25T07:58:41+02:00
Associate some older Cloudflare Quiche issues with itp'ed entry
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -29782,7 +29782,7 @@ CVE-2026-12238 (The WP Go Maps \u2013 Most Popular Map Plugin plugin for WordPre
CVE-2026-12104 (OS command injection in the environment and tunnel configuration funct ...)
NOT-FOR-US: SIMA GmbH Bondix
CVE-2026-11941 (Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in ...)
- NOT-FOR-US: Cloudflare Quiche
+ - quiche <itp> (bug #841848)
CVE-2026-11576 (The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refacto ...)
NOT-FOR-US: Eclipse
CVE-2025-71326 (AVAST Antivirus 25.11 contains an unquoted service path vulnerability ...)
@@ -332785,7 +332785,7 @@ CVE-2024-21330 (Open Management Infrastructure (OMI) Elevation of Privilege Vuln
CVE-2024-20671 (Microsoft Defender Security Feature Bypass Vulnerability)
NOT-FOR-US: Microsoft
CVE-2024-1765 (Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an u ...)
- NOT-FOR-US: Cloudflare quiche
+ - quiche <itp> (bug #841848)
CVE-2024-1618 (A search path or unquoted item vulnerability in Faronics Deep Freeze S ...)
NOT-FOR-US: Faronics Deep Freeze Server Standard
CVE-2024-1529 (Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently e ...)
@@ -332795,7 +332795,7 @@ CVE-2024-1528 (CMS Made Simple version 2.2.14, does not sufficiently encode user
CVE-2024-1527 (Unrestricted file upload vulnerability in CMS Made Simple, affecting v ...)
NOT-FOR-US: CMS Made Simple
CVE-2024-1410 (Cloudflare quiche was discovered to be vulnerable to unbounded storage ...)
- NOT-FOR-US: Cloudflare quiche
+ - quiche <itp> (bug #841848)
CVE-2024-1328 (The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-S ...)
NOT-FOR-US: WordPress plugin
CVE-2024-1304 (Cross-site scripting vulnerability in Badger Meter Monitool that affec ...)
@@ -352685,7 +352685,7 @@ CVE-2023-6593 (Client side permission bypass in Devolutions Remote Desktop Manag
CVE-2023-6547 (Mattermost fails to validate team membership when a user attempts to a ...)
- mattermost-server <itp> (bug #823556)
CVE-2023-6193 (quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unb ...)
- NOT-FOR-US: Cloudflare quiche
+ - quiche <itp> (bug #841848)
CVE-2023-50495 (NCurse v6.4-20230418 was discovered to contain a segmentation fault vi ...)
- ncurses 6.4+20230625-1
[bookworm] - ncurses <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a916f5c2a8fb52edb14b806462c166149066c7d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a916f5c2a8fb52edb14b806462c166149066c7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/2318515d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list