Cisco IOS XR Software Denial of Service Vulnerability

A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to ...

Continue Reading
CVE-2017-6599

A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

PYSEC-2017-101

Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.Read More ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Denial Of Service (DoS)

github.com/andreimatei/grpc-go is vulnerable to denial of service (DoS) attacks. A malicious user can send an empty hpack string to the system and cause it to crash.Read More ...

Continue Reading
Cisco IOS XR Software Event Management Service gRPC Handling DoS (cisco-sa-20170503-ios-xr)

According to its self-reported version and configuration, the Cisco IOS XR software running on the remote device is affected by a denial of service vulnerability in the Event Management Service daemon ...

Continue Reading
Gitlab — multiple vulnerabilities

Gitlab reports: SSRF GCP access token disclosure Persistent XSS on issue details Diff formatter DoS in Sidekiq jobs Confidential information disclosure in events API endpoint validate_localhost functi ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

FreeBSD : Gitlab — multiple vulnerabilities (065b3b72-c5ab-11e8-9ae2-001b217b3468)

Gitlab reports : SSRF GCP access token disclosure Persistent XSS on issue details Diff formatter DoS in Sidekiq jobs Confidential information disclosure in events API endpoint validate_localhost funct ...

Continue Reading
Happy graduation, Envoy!

Envoy, the new darling of the DevOps community, performs the role of a service and edge proxy. With advanced features such as timeouts, rate limiting, circuit breaking, load balancing, retries, stats, ...

Continue Reading

Back to Main

Subscribe for the latest news: