CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
there is a possible cellular denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. |
In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. |
It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It's also possible to use this vulnerability to leak other clients HTTP header keys, but not values.
This occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.
Please update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4. |
Microsoft Office Graphics Remote Code Execution Vulnerability |
Microsoft Office Graphics Remote Code Execution Vulnerability |
Microsoft Office Graphics Remote Code Execution Vulnerability |
Microsoft Outlook for Mac Spoofing Vulnerability |
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
Azure Network Watcher Agent Security Feature Bypass Vulnerability |
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
Raw Image Extension Remote Code Execution Vulnerability |
Windows Graphics Component Elevation of Privilege Vulnerability |
Windows Graphics Component Elevation of Privilege Vulnerability |
Windows Fax Compose Form Elevation of Privilege Vulnerability |
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability |
PowerShell Remote Code Execution Vulnerability |
Windows Graphics Component Information Disclosure Vulnerability |
Windows Hyper-V Elevation of Privilege Vulnerability |
.NET Framework Remote Code Execution Vulnerability |
Microsoft Office Graphics Remote Code Execution Vulnerability |