Vulnerability index

Browse CVEs

122 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Proxygen CRITICAL 9.8
CVE-2020-1897

A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in …

Fix: 2020.05.18.00+
Fix from $2,300 2020-05-18
Instagram HIGH 7.8
CVE-2020-1895

A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dimensions. This affects version…

Fix: 128.0.0.26.128+
Fix from $1,950 2020-04-09
Thrift HIGH 7.5
CVE-2019-11939

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious …

Fix: 2020.03.16.00+
Fix from $1,950 2020-03-18
Thrift HIGH 7.5
CVE-2019-11938

Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cl…

Fix: 2019.12.09.00+
Fix from $1,950 2020-03-10
Thrift HIGH 7.5
CVE-2019-3553

C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cli…

Fix: 2020.02.03.00+
Fix from $1,950 2020-03-10
Hhvm HIGH 7.5
CVE-2020-1893

Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4…

Fix: 4.8.7+
Fix from $1,950 2020-03-03
Hhvm HIGH 8.1
CVE-2020-1892

Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to information leak an…

Fix: 4.8.7+
Fix from $1,950 2020-03-03
Hhvm HIGH 7.5
CVE-2020-1888

Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.…

Fix: 4.8.7+
Fix from $1,950 2020-03-03
Hhvm CRITICAL 9.8
CVE-2016-1000004

Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM v…

Fix: 3.9.5+
Fix from $2,300 2020-02-19
Hhvm CRITICAL 9.8
CVE-2016-1000005

mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed…

Fix: 3.9.5+
Fix from $2,300 2020-02-19
Hhvm MEDIUM 5.3
CVE-2016-1000109EPSS 5%

HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of unt…

Fix: 3.9.6+
Fix from $1,600 2020-02-19
Hhvm CRITICAL 9.8
CVE-2019-11930

An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM version…

Fix: 3.30.12+
Fix from $2,300 2019-12-04
Folly CRITICAL 9.8
CVE-2019-11934

Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.

Fix: 2019.11.04.00+
Fix from $2,300 2019-12-04
Hhvm CRITICAL 9.8
CVE-2019-11935

Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prio…

Fix: 3.30.12+
Fix from $2,300 2019-12-04
Hhvm CRITICAL 9.8
CVE-2019-11936

Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to…

Fix: 3.30.12+
Fix from $2,300 2019-12-04
Proxygen CRITICAL 9.8
CVE-2019-11940

In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table i…

Fix: after 2017.04.03.00
Fix from $2,300 2019-12-04
Mcrouter HIGH 7.5
CVE-2019-11923

In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowin…

Fix: 0.41.0+
Fix from $1,950 2019-12-04
Mcrouter HIGH 7.5
CVE-2019-11937

In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.

Fix: 0.41.0+
Fix from $1,950 2019-12-04
Hhvm CRITICAL 9.8
CVE-2016-1000006

hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.

Fix: 3.12.11+
Fix from $2,300 2019-11-19
Hhvm CRITICAL 9.8
CVE-2019-11929

Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote…

Fix: 3.30.10+
Fix from $2,300 2019-10-02
Hhvm CRITICAL 9.8
CVE-2019-11925

Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a malicio…

Fix: after 4.20.1
Fix from $2,300 2019-09-06
Hhvm CRITICAL 9.8
CVE-2019-11926

Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a ma…

Fix: after 4.20.1
Fix from $2,300 2019-09-06
Facebook For Woocommerce HIGH 8.8
CVE-2019-15840

The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.

Fix: 1.9.14+
Fix from $1,950 2019-08-30
Facebook For Woocommerce HIGH 8.8
CVE-2019-15841

The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_f…

Fix: 1.9.15+
Fix from $1,950 2019-08-30
Fizz HIGH 7.5
CVE-2019-11924

A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in m…

Fix: after 2019.08.05.00
Fix from $1,950 2019-08-20
Proxygen CRITICAL 9.8
CVE-2019-11921

An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsi…

Fix: 2019.07.22.00+
Fix from $2,300 2019-07-25
Zstandard HIGH 8.1
CVE-2019-11922

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an…

Fix: 1.3.8+
Fix from $1,950 2019-07-25
Hiphop Virtual Machine CRITICAL 9.8
CVE-2019-3570

Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the para…

Fix: after 4.0.4
Fix from $2,300 2019-07-18
Hhvm HIGH 7.5
CVE-2019-3569

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct a…

Fix: after 3.30.5
Fix from $1,950 2019-06-26
Thrift HIGH 7.5
CVE-2019-3559

Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could …

Fix: 2019.02.18.00+
Fix from $1,950 2019-05-06