Skip to content
Noroxi

grpc records

15 published records for vendor grpc.

Researcher profile

Entered KEV
1 · 6.7%
Weaponized
1 · 6.7%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
0 days

All records

15 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

    CriticalCVSS 9.8No exploitEPSS 4%

    grpc · grpcNov 11, 2020

  • Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/e

    CriticalCVSS 9.8No exploitEPSS 3%

    grpc · grpcApr 14, 2017

  • Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in

    CriticalCVSS 9.8No exploitEPSS 3%

    grpc · grpcApr 30, 2017

  • Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.

    CriticalCVSS 9.8No exploitEPSS 3%

    grpc · grpcApr 14, 2017

  • Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.

    CriticalCVSS 9.8No exploitEPSS 2%

    grpc · grpcJun 4, 2017

  • gRPC-Go has an authorization bypass via missing leading slash in :path

    CriticalCVSS 9.1Proof of conceptEPSS 2%

    grpc · grpcMar 20, 2026

  • CVE-2023-4785
    30Monitor

    Denial of Service in gRPC Core

    HighCVSS 7.5No exploitEPSS 1%

    grpc · grpcSep 13, 2023

  • Information leak in gRPC

    HighCVSS 7.5No exploitEPSS 0%

    grpc · grpcJun 9, 2023

  • Denial-of-Service in gRPC

    HighCVSS 7.5No exploitEPSS 0%

    grpc · grpcAug 9, 2023

  • CVE-2023-1428
    30Monitor

    Denial-of-Service in gRPC

    HighCVSS 7.5No exploitEPSS 0%

    grpc · grpcJun 9, 2023

  • Denial of Service through Data corruption in gRPC-C++

    MediumCVSS 6.9No exploitEPSS 1%

    grpc · grpcNov 26, 2024

  • CVE-2024-7246
    25Monitor

    HPACK table poisoning in gRPC C++, Python & Ruby

    MediumCVSS 6.3No exploitEPSS 0%

    grpc · grpcAug 6, 2024

  • @grpc/grpc-js can allocate memory for incoming messages well above configured limits

    MediumCVSS 5.3No exploitEPSS 1%

    grpc · grpc-nodeJun 10, 2024

  • Denial-of-Service in gRPC

    MediumCVSS 5.3No exploitEPSS 1%

    grpc · grpcJun 9, 2023