Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2022-24777

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when handling GOAWAY frames. The attack is low-effort: it takes very little resources to construct and send the required sequence of frames. The impact on availability is high as the server will crash, dropping all in flight connections and requests. This issue is fixed in version 1.7.2. There are currently no known workarounds.
Attacker Value
Unknown

CVE-2021-36153

Disclosure Date: July 09, 2021 (last updated November 28, 2024)
Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed requests.
Attacker Value
Unknown

CVE-2021-36155

Disclosure Date: July 09, 2021 (last updated November 28, 2024)
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.
Attacker Value
Unknown

CVE-2021-36154

Disclosure Date: July 09, 2021 (last updated November 28, 2024)
HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumption.
Attacker Value
Unknown

CVE-2020-7768

Disclosure Date: November 11, 2020 (last updated November 28, 2024)
The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.
Attacker Value
Unknown

CVE-2017-9431

Disclosure Date: June 05, 2017 (last updated November 26, 2024)
Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.
0
Attacker Value
Unknown

CVE-2017-8359

Disclosure Date: April 30, 2017 (last updated November 26, 2024)
Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.
0
Attacker Value
Unknown

CVE-2017-7860

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.
0
Attacker Value
Unknown

CVE-2017-7861

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
0
Attacker Value
Unknown

CVE-2004-0572

Disclosure Date: November 03, 2004 (last updated October 04, 2023)
Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.
0