Vulnerability index

Browse CVEs

122 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thrift HIGH 7.5
CVE-2019-3564

Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could se…

Fix: 2019.03.04.00+
Fix from $1,950 2019-05-06
Thrift HIGH 7.5
CVE-2019-3565

Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As …

Fix: 2019.05.06.00+
Fix from $1,950 2019-05-06
Thrift HIGH 7.5
CVE-2019-3552

C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious cl…

Fix: 2019.02.18.00+
Fix from $1,950 2019-05-06
Thrift HIGH 7.5
CVE-2019-3558

Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients coul…

Fix: 2019.02.18.00+
Fix from $1,950 2019-05-06
Wangle CRITICAL 9.8
CVE-2019-3563

Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This af…

Fix: 2019.04.22.00+
Fix from $2,300 2019-04-29
Hhvm CRITICAL 9.8
CVE-2019-3561

Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM…

Fix: after 4.0.3
Fix from $2,300 2019-04-29
Fizz HIGH 7.5
CVE-2019-3560

An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user inp…

Fix: 2019.03.04.00+
Fix from $1,950 2019-04-29
Hhvm CRITICAL 9.8
CVE-2018-6345

The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implement…

Fix: after 3.30.1
Fix from $2,300 2019-01-15
Hhvm CRITICAL 9.8
CVE-2019-3557

The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior cau…

Fix: after 3.30.0
Fix from $2,300 2019-01-15
Wangle MEDIUM 5.9
CVE-2019-3554

Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against…

Fix: 2019.01.14.00+
Fix from $1,600 2019-01-15
Buck CRITICAL 9.8
CVE-2018-6331

Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lea…

Fix: 2018.06.25.01+
Fix from $2,300 2018-12-31
Nuclide CRITICAL 9.8
CVE-2018-6333

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL c…

Fix: 0.290.0+
Fix from $2,300 2018-12-31
React Dev Utils CRITICAL 9.8
CVE-2018-6342

react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The in…

Fix: 1.0.4 / 2.0.2+
Fix from $2,300 2018-12-31
Hhvm HIGH 8.1
CVE-2018-6340

The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server ho…

Fix: after 3.27.4
Fix from $1,950 2018-12-31
Folly HIGH 7.5
CVE-2018-6337

folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children produ…

Fix: 3.26.3+
Fix from $1,950 2018-12-31
Proxygen HIGH 7.5
CVE-2018-6343

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Cert…

Fix: 2018.11.19.00+
Fix from $1,950 2018-12-31
React MEDIUM 6.1
CVE-2018-6341

React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of e…

Fix: 16.0.1 / 16.1.2+
Fix from $1,600 2018-12-31
Hhvm CRITICAL 9.8
CVE-2018-6334

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before be…

Fix: after 3.25.1
Fix from $2,300 2018-12-31
Hhvm HIGH 7.5
CVE-2018-6335

A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affec…

Fix: after 3.21.10
Fix from $1,950 2018-12-31
Hhvm MEDIUM 5.9
CVE-2018-6332

A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources…

Fix: after 3.21.7
Fix from $1,600 2018-12-03
Hhvm CRITICAL 9.8
CVE-2016-6871

Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer ov…

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Hhvm CRITICAL 9.8
CVE-2016-6872

Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Hhvm CRITICAL 9.8
CVE-2016-6873

Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Hhvm CRITICAL 9.8
CVE-2016-6874

The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion.

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Hhvm CRITICAL 9.8
CVE-2016-6875

Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Hhvm CRITICAL 9.8
CVE-2016-6870

Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attacker…

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Hiphop Virtual Machine MEDIUM 5.0
CVE-2014-6229

The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key …

Fix: after 3.2.0
Fix from $1,600 2014-12-28
Hiphop Virtual Machine HIGH 7.5
CVE-2014-6228

Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allow…

Fix: after 3.2.0
Fix from $1,950 2014-12-28
Hiphop Virtual Machine MEDIUM 5.0
CVE-2014-5386

The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the rand…

Fix: after 3.2.0
Fix from $1,600 2014-12-28
Hiphop Virtual Machine MEDIUM 5.0
CVE-2014-2209

Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-…

Fix: after 3.0.1
Fix from $1,600 2014-12-28