Записи grpc
15 опубликованных записей вендора grpc.
Профиль для исследователя
- Попали в KEV
- 1 · 6,7 %
- С эксплойтом
- 1 · 6,7 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-787 Out-of-bounds Write4
- CWE-440 Expected Behavior Violation3
- CWE-789 Memory Allocation with Excessive Size Value2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-285 Improper Authorization1
- CWE-617 Reachable Assertion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
40В плане | CVE-2020-7768Эксплойта нет | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.grpc · grpc · CWE-1321 | Критическая9,8 | — | 4,2 % | 11 нояб. 2020 г. |
40В плане | CVE-2017-7860Эксплойта нет | Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/egrpc · grpc · CWE-787 | Критическая9,8 | — | 3,1 % | 14 апр. 2017 г. |
40В плане | CVE-2017-8359Эксплойта нет | Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in grpc · grpc · CWE-787 | Критическая9,8 | — | 3,1 % | 30 апр. 2017 г. |
40В плане | CVE-2017-7861Эксплойта нет | Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.grpc · grpc · CWE-787 | Критическая9,8 | — | 2,9 % | 14 апр. 2017 г. |
40В плане | CVE-2017-9431Эксплойта нет | Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.grpc · grpc · CWE-787 | Критическая9,8 | — | 2,4 % | 4 июн. 2017 г. |
36Наблюдать | CVE-2026-33186Proof of concept | gRPC-Go has an authorization bypass via missing leading slash in :pathgrpc · grpc · CWE-285 | Критическая9,1 | — | 1,6 % | 20 мар. 2026 г. |
30Наблюдать | CVE-2023-4785Эксплойта нет | Denial of Service in gRPC Coregrpc · grpc · CWE-248 | Высокая7,5 | — | 0,8 % | 13 сент. 2023 г. |
30Наблюдать | CVE-2023-32731Эксплойта нет | Information leak in gRPCgrpc · grpc · CWE-440 | Высокая7,5 | — | 0,5 % | 9 июн. 2023 г. |
30Наблюдать | CVE-2023-33953Эксплойта нет | Denial-of-Service in gRPCgrpc · grpc · CWE-789 | Высокая7,5 | — | 0,5 % | 9 авг. 2023 г. |
30Наблюдать | CVE-2023-1428Эксплойта нет | Denial-of-Service in gRPCgrpc · grpc · CWE-617 | Высокая7,5 | — | 0,4 % | 9 июн. 2023 г. |
27Наблюдать | CVE-2024-11407Эксплойта нет | Denial of Service through Data corruption in gRPC-C++grpc · grpc · CWE-682 | Средняя6,9 | — | 0,6 % | 26 нояб. 2024 г. |
25Наблюдать | CVE-2024-7246Эксплойта нет | HPACK table poisoning in gRPC C++, Python & Rubygrpc · grpc · CWE-440 | Средняя6,3 | — | 0,2 % | 6 авг. 2024 г. |
21Наблюдать | CVE-2024-37168Эксплойта нет | @grpc/grpc-js can allocate memory for incoming messages well above configured limitsgrpc · grpc-node · CWE-789 | Средняя5,3 | — | 0,7 % | 10 июн. 2024 г. |
21Наблюдать | CVE-2023-32732Эксплойта нет | Denial-of-Service in gRPCgrpc · grpc · CWE-440 | Средняя5,3 | — | 0,5 % | 9 июн. 2023 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2020-776840В плане
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %grpc · grpc11 нояб. 2020 г.
- CVE-2017-786040В плане
Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/e
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %grpc · grpc14 апр. 2017 г.
- CVE-2017-835940В плане
Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %grpc · grpc30 апр. 2017 г.
- CVE-2017-786140В плане
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %grpc · grpc14 апр. 2017 г.
- CVE-2017-943140В плане
Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %grpc · grpc4 июн. 2017 г.
- CVE-2026-3318636Наблюдать
gRPC-Go has an authorization bypass via missing leading slash in :path
КритическаяCVSS 9,1Proof of conceptEPSS 2 %grpc · grpc20 мар. 2026 г.
- CVE-2023-478530Наблюдать
Denial of Service in gRPC Core
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %grpc · grpc13 сент. 2023 г.
- CVE-2023-3273130Наблюдать
Information leak in gRPC
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %grpc · grpc9 июн. 2023 г.
- CVE-2023-3395330Наблюдать
Denial-of-Service in gRPC
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %grpc · grpc9 авг. 2023 г.
- CVE-2023-142830Наблюдать
Denial-of-Service in gRPC
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %grpc · grpc9 июн. 2023 г.
- CVE-2024-1140727Наблюдать
Denial of Service through Data corruption in gRPC-C++
СредняяCVSS 6,9Эксплойта нетEPSS 1 %grpc · grpc26 нояб. 2024 г.
- CVE-2024-724625Наблюдать
HPACK table poisoning in gRPC C++, Python & Ruby
СредняяCVSS 6,3Эксплойта нетEPSS 0 %grpc · grpc6 авг. 2024 г.
- CVE-2024-3716821Наблюдать
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
СредняяCVSS 5,3Эксплойта нетEPSS 1 %grpc · grpc-node10 июн. 2024 г.
- CVE-2023-3273221Наблюдать
Denial-of-Service in gRPC
СредняяCVSS 5,3Эксплойта нетEPSS 1 %grpc · grpc9 июн. 2023 г.