Vulnerability index

Browse CVEs

122 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-1897 A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in … Proxygen 2020.05.18.00+ Fix from $2,3002020-05-18 HIGH 7.8 CVE-2020-1895 A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dimensions. This affects version… Instagram 128.0.0.26.128+ Fix from $1,9502020-04-09 HIGH 7.5 CVE-2019-11939 Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious … Thrift 2020.03.16.00+ Fix from $1,9502020-03-18 HIGH 7.5 CVE-2019-11938 Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cl… Thrift 2019.12.09.00+ Fix from $1,9502020-03-10 HIGH 7.5 CVE-2019-3553 C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious cli… Thrift 2020.02.03.00+ Fix from $1,9502020-03-10 HIGH 7.5 CVE-2020-1893 Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4… Hhvm 4.8.7+ Fix from $1,9502020-03-03 HIGH 8.1 CVE-2020-1892 Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to information leak an… Hhvm 4.8.7+ Fix from $1,9502020-03-03 HIGH 7.5 CVE-2020-1888 Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.… Hhvm 4.8.7+ Fix from $1,9502020-03-03 CRITICAL 9.8 CVE-2016-1000004 Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM v… Hhvm 3.9.5+ Fix from $2,3002020-02-19 CRITICAL 9.8 CVE-2016-1000005 mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed… Hhvm 3.9.5+ Fix from $2,3002020-02-19 MEDIUM 5.3 CVE-2016-1000109EPSS 5% HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of unt… Hhvm 3.9.6+ Fix from $1,6002020-02-19 CRITICAL 9.8 CVE-2019-11930 An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM version… Hhvm 3.30.12+ Fix from $2,3002019-12-04 CRITICAL 9.8 CVE-2019-11934 Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00. Folly 2019.11.04.00+ Fix from $2,3002019-12-04 CRITICAL 9.8 CVE-2019-11935 Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prio… Hhvm 3.30.12+ Fix from $2,3002019-12-04 CRITICAL 9.8 CVE-2019-11936 Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to… Hhvm 3.30.12+ Fix from $2,3002019-12-04 CRITICAL 9.8 CVE-2019-11940 In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table i… Proxygen after 2017.04.03.00 Fix from $2,3002019-12-04 HIGH 7.5 CVE-2019-11923 In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowin… Mcrouter 0.41.0+ Fix from $1,9502019-12-04 HIGH 7.5 CVE-2019-11937 In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service. Mcrouter 0.41.0+ Fix from $1,9502019-12-04 CRITICAL 9.8 CVE-2016-1000006 hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions. Hhvm 3.12.11+ Fix from $2,3002019-11-19 CRITICAL 9.8 CVE-2019-11929 Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote… Hhvm 3.30.10+ Fix from $2,3002019-10-02 CRITICAL 9.8 CVE-2019-11925 Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a malicio… Hhvm after 4.20.1 Fix from $2,3002019-09-06 CRITICAL 9.8 CVE-2019-11926 Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a ma… Hhvm after 4.20.1 Fix from $2,3002019-09-06 HIGH 8.8 CVE-2019-15840 The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. Facebook For Woocommerce 1.9.14+ Fix from $1,9502019-08-30 HIGH 8.8 CVE-2019-15841 The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_f… Facebook For Woocommerce 1.9.15+ Fix from $1,9502019-08-30 HIGH 7.5 CVE-2019-11924 A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in m… Fizz after 2019.08.05.00 Fix from $1,9502019-08-20 CRITICAL 9.8 CVE-2019-11921 An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsi… Proxygen 2019.07.22.00+ Fix from $2,3002019-07-25 HIGH 8.1 CVE-2019-11922 A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an… Zstandard 1.3.8+ Fix from $1,9502019-07-25 CRITICAL 9.8 CVE-2019-3570 Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the para… Hiphop Virtual Machine after 4.0.4 Fix from $2,3002019-07-18 HIGH 7.5 CVE-2019-3569 HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct a… Hhvm after 3.30.5 Fix from $1,9502019-06-26 HIGH 7.5 CVE-2019-3559 Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could … Thrift 2019.02.18.00+ Fix from $1,9502019-05-06