Uncontrolled Resource Consumption in LengthPrefixedMessageReader
### Impact
Affected gRPC Swift clients and servers are vulnerable to uncontrolled resource consumption attacks. Excessive memory may be allocated when parsing messages. This can lead to a denial of se ...
Continue Reading
June 19, 2023
Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec
### Impact
Affected gRPC Swift servers are vulnerable to precondition failures when parsing certain gRPC Web requests. This may lead to a denial of service.
### Patches
The problem has been fixed in 1 ...
Continue Reading
June 19, 2023
Denial of Service via reachable assertion
A grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This was due to incorrect logic when handling `GOAWAY` frames.
The attack is low-effort: it takes very little ...
Continue Reading
June 19, 2023
(RHSA-2023:3660) Important: c-ares security update
The c-ares C library defines asynchronous DNS (Domain Name System) requests and provides name resolving API.
Security Fix(es):
* c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067)
For more ...
Continue Reading
June 19, 2023
CVE-2023-28287
Microsoft Publisher Remote Code Execution VulnerabilityRead More ...
Continue Reading
June 17, 2023
CVE-2023-28295
Microsoft Publisher Remote Code Execution VulnerabilityRead More ...
Continue Reading
June 17, 2023
CVE-2023-3295
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functional ...
Continue Reading
June 17, 2023
CVE-2023-32731
When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of ...
Continue Reading
June 16, 2023
CVE-2023-32031
Microsoft Exchange Server Remote Code Execution VulnerabilityRead More ...
Continue Reading
June 14, 2023
CVE-2023-32030
.NET and Visual Studio Denial of Service VulnerabilityRead More ...
Continue Reading
June 14, 2023