Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2021-24044
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke ge…
Hermes
0.10.0+
CRITICAL 9.8
CVE-2021-24045
A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is o…
Hermes
0.10.0+
HIGH 8.1
CVE-2019-3556
HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be us…
Hhvm
4.56.2+
HIGH 8.8
CVE-2021-39207
parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is v…
Parlai
1.1.0+
CRITICAL 9.8
CVE-2021-24040EPSS 17%
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input,…
Parlai
1.1.0+
CRITICAL 9.8
CVE-2021-24036
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possi…
Folly
4.80.5 / 2021.07.22.00+
CRITICAL 9.8
CVE-2021-24037
A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to poten…
Hermes
0.8.0+
HIGH 7.5
CVE-2020-1920
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, be…
React Native
0.64.1+
CRITICAL 9.8
CVE-2021-24028
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable…
Thrift
2021.02.22.00+
HIGH 8.8
CVE-2021-24218
The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF …
Facebook
3.0.4+
HIGH 8.1
CVE-2021-24217
The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be su…
Facebook
3.0.0+
HIGH 7.5
CVE-2021-24029
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. P…
Mvfst
2021-03-13 / 2021.03.15.00+
CRITICAL 9.8
CVE-2020-1900
When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything …
Hhvm
4.32.3 / 4.56.1+
HIGH 7.5
CVE-2020-1898
The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserial…
Hhvm
4.32.3 / 4.56.1+
HIGH 7.5
CVE-2020-1899
The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary m…
Hhvm
4.32.3 / 4.56.1+
CRITICAL 9.8
CVE-2021-24025
Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow…
Hhvm
4.56.3+
CRITICAL 9.8
CVE-2021-24030
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malici…
Gameroom
1.26.0+
CRITICAL 9.8
CVE-2020-1916
An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write…
Hhvm
4.56.2 / 4.78.1+
CRITICAL 9.8
CVE-2020-1917
xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its stan…
Hhvm
4.56.3 / 4.80.2+
HIGH 7.5
CVE-2020-1918
In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory prior to the…
Hhvm
4.56.3 / 4.80.2+
HIGH 7.5
CVE-2020-1919
Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the firs…
Hhvm
4.56.3 / 4.80.2+
HIGH 7.5
CVE-2020-1921
In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer…
Hhvm
4.56.3 / 4.80.2+
MEDIUM 5.6
CVE-2021-24033
react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed.…
React Dev Utils
11.0.4+
MEDIUM 5.5
CVE-2021-24031
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the inp…
Zstandard
1.4.1+
CRITICAL 9.8
CVE-2020-1896
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.com/facebo…
Hermes
0.5.0+
HIGH 7.5
CVE-2020-1915
An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to c…
Hermes
2020-09-25+
CRITICAL 9.8
CVE-2020-1914
A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7fdddfc all…
Hermes
2020-10-01+
HIGH 8.1
CVE-2020-1913
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attacker…
Hermes
after 0.4.3
HIGH 8.1
CVE-2020-1912
An out-of-bounds read/write vulnerability when executing lazily compiled inner generator functions in Facebook Hermes prior to commit 091835377369c8f…
Hermes
after 0.4.3
CRITICAL 9.8
CVE-2020-1911
A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prior to co…
Hermes
0.4.3+