grpc kayıtları
grpc üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %6,7
- Silahlaştırılmış
- 1 · %6,7
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write4
- CWE-440 Expected Behavior Violation3
- CWE-789 Memory Allocation with Excessive Size Value2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-285 Improper Authorization1
- CWE-617 Reachable Assertion1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
40Planlayın | CVE-2020-7768İstismar yok | The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.grpc · grpc · CWE-1321 | Kritik9,8 | — | %4,2 | 11 Kas 2020 |
40Planlayın | CVE-2017-7860İstismar yok | Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/egrpc · grpc · CWE-787 | Kritik9,8 | — | %3,1 | 14 Nis 2017 |
40Planlayın | CVE-2017-8359İstismar yok | Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in grpc · grpc · CWE-787 | Kritik9,8 | — | %3,1 | 30 Nis 2017 |
40Planlayın | CVE-2017-7861İstismar yok | Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.grpc · grpc · CWE-787 | Kritik9,8 | — | %2,9 | 14 Nis 2017 |
40Planlayın | CVE-2017-9431İstismar yok | Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.grpc · grpc · CWE-787 | Kritik9,8 | — | %2,4 | 4 Haz 2017 |
36İzleyin | CVE-2026-33186Kavram kanıtı | gRPC-Go has an authorization bypass via missing leading slash in :pathgrpc · grpc · CWE-285 | Kritik9,1 | — | %1,6 | 20 Mar 2026 |
30İzleyin | CVE-2023-4785İstismar yok | Denial of Service in gRPC Coregrpc · grpc · CWE-248 | Yüksek7,5 | — | %0,8 | 13 Eyl 2023 |
30İzleyin | CVE-2023-32731İstismar yok | Information leak in gRPCgrpc · grpc · CWE-440 | Yüksek7,5 | — | %0,5 | 9 Haz 2023 |
30İzleyin | CVE-2023-33953İstismar yok | Denial-of-Service in gRPCgrpc · grpc · CWE-789 | Yüksek7,5 | — | %0,5 | 9 Ağu 2023 |
30İzleyin | CVE-2023-1428İstismar yok | Denial-of-Service in gRPCgrpc · grpc · CWE-617 | Yüksek7,5 | — | %0,4 | 9 Haz 2023 |
27İzleyin | CVE-2024-11407İstismar yok | Denial of Service through Data corruption in gRPC-C++grpc · grpc · CWE-682 | Orta6,9 | — | %0,6 | 26 Kas 2024 |
25İzleyin | CVE-2024-7246İstismar yok | HPACK table poisoning in gRPC C++, Python & Rubygrpc · grpc · CWE-440 | Orta6,3 | — | %0,2 | 6 Ağu 2024 |
21İzleyin | CVE-2024-37168İstismar yok | @grpc/grpc-js can allocate memory for incoming messages well above configured limitsgrpc · grpc-node · CWE-789 | Orta5,3 | — | %0,7 | 10 Haz 2024 |
21İzleyin | CVE-2023-32732İstismar yok | Denial-of-Service in gRPCgrpc · grpc · CWE-440 | Orta5,3 | — | %0,5 | 9 Haz 2023 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2020-776840Planlayın
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
KritikCVSS 9,8İstismar yokEPSS %4grpc · grpc11 Kas 2020
- CVE-2017-786040Planlayın
Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/e
KritikCVSS 9,8İstismar yokEPSS %3grpc · grpc14 Nis 2017
- CVE-2017-835940Planlayın
Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in
KritikCVSS 9,8İstismar yokEPSS %3grpc · grpc30 Nis 2017
- CVE-2017-786140Planlayın
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
KritikCVSS 9,8İstismar yokEPSS %3grpc · grpc14 Nis 2017
- CVE-2017-943140Planlayın
Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.
KritikCVSS 9,8İstismar yokEPSS %2grpc · grpc4 Haz 2017
- CVE-2026-3318636İzleyin
gRPC-Go has an authorization bypass via missing leading slash in :path
KritikCVSS 9,1Kavram kanıtıEPSS %2grpc · grpc20 Mar 2026
- CVE-2023-478530İzleyin
Denial of Service in gRPC Core
YüksekCVSS 7,5İstismar yokEPSS %1grpc · grpc13 Eyl 2023
- CVE-2023-3273130İzleyin
Information leak in gRPC
YüksekCVSS 7,5İstismar yokEPSS %0grpc · grpc9 Haz 2023
- CVE-2023-3395330İzleyin
Denial-of-Service in gRPC
YüksekCVSS 7,5İstismar yokEPSS %0grpc · grpc9 Ağu 2023
- CVE-2023-142830İzleyin
Denial-of-Service in gRPC
YüksekCVSS 7,5İstismar yokEPSS %0grpc · grpc9 Haz 2023
- CVE-2024-1140727İzleyin
Denial of Service through Data corruption in gRPC-C++
OrtaCVSS 6,9İstismar yokEPSS %1grpc · grpc26 Kas 2024
- CVE-2024-724625İzleyin
HPACK table poisoning in gRPC C++, Python & Ruby
OrtaCVSS 6,3İstismar yokEPSS %0grpc · grpc6 Ağu 2024
- CVE-2024-3716821İzleyin
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
OrtaCVSS 5,3İstismar yokEPSS %1grpc · grpc-node10 Haz 2024
- CVE-2023-3273221İzleyin
Denial-of-Service in gRPC
OrtaCVSS 5,3İstismar yokEPSS %1grpc · grpc9 Haz 2023