Vulnerability index

Browse CVEs

122 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-3564 Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could se… Thrift 2019.03.04.00+ Fix from $1,9502019-05-06 HIGH 7.5 CVE-2019-3565 Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As … Thrift 2019.05.06.00+ Fix from $1,9502019-05-06 HIGH 7.5 CVE-2019-3552 C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious cl… Thrift 2019.02.18.00+ Fix from $1,9502019-05-06 HIGH 7.5 CVE-2019-3558 Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients coul… Thrift 2019.02.18.00+ Fix from $1,9502019-05-06 CRITICAL 9.8 CVE-2019-3563 Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This af… Wangle 2019.04.22.00+ Fix from $2,3002019-04-29 CRITICAL 9.8 CVE-2019-3561 Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM… Hhvm after 4.0.3 Fix from $2,3002019-04-29 HIGH 7.5 CVE-2019-3560 An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user inp… Fizz 2019.03.04.00+ Fix from $1,9502019-04-29 CRITICAL 9.8 CVE-2018-6345 The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implement… Hhvm after 3.30.1 Fix from $2,3002019-01-15 CRITICAL 9.8 CVE-2019-3557 The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior cau… Hhvm after 3.30.0 Fix from $2,3002019-01-15 MEDIUM 5.9 CVE-2019-3554 Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against… Wangle 2019.01.14.00+ Fix from $1,6002019-01-15 CRITICAL 9.8 CVE-2018-6331 Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lea… Buck 2018.06.25.01+ Fix from $2,3002018-12-31 CRITICAL 9.8 CVE-2018-6333 The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL c… Nuclide 0.290.0+ Fix from $2,3002018-12-31 CRITICAL 9.8 CVE-2018-6342 react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The in… React Dev Utils 1.0.4 / 2.0.2+ Fix from $2,3002018-12-31 HIGH 8.1 CVE-2018-6340 The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server ho… Hhvm after 3.27.4 Fix from $1,9502018-12-31 HIGH 7.5 CVE-2018-6337 folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children produ… Folly 3.26.3+ Fix from $1,9502018-12-31 HIGH 7.5 CVE-2018-6343 Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Cert… Proxygen 2018.11.19.00+ Fix from $1,9502018-12-31 MEDIUM 6.1 CVE-2018-6341 React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of e… React 16.0.1 / 16.1.2+ Fix from $1,6002018-12-31 CRITICAL 9.8 CVE-2018-6334 Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before be… Hhvm after 3.25.1 Fix from $2,3002018-12-31 HIGH 7.5 CVE-2018-6335 A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affec… Hhvm after 3.21.10 Fix from $1,9502018-12-31 MEDIUM 5.9 CVE-2018-6332 A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources… Hhvm after 3.21.7 Fix from $1,6002018-12-03 CRITICAL 9.8 CVE-2016-6871 Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer ov… Hhvm after 3.14.5 Fix from $2,3002017-02-17 CRITICAL 9.8 CVE-2016-6872 Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. Hhvm after 3.14.5 Fix from $2,3002017-02-17 CRITICAL 9.8 CVE-2016-6873 Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. Hhvm after 3.14.5 Fix from $2,3002017-02-17 CRITICAL 9.8 CVE-2016-6874 The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion. Hhvm after 3.14.5 Fix from $2,3002017-02-17 CRITICAL 9.8 CVE-2016-6875 Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. Hhvm after 3.14.5 Fix from $2,3002017-02-17 CRITICAL 9.8 CVE-2016-6870 Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attacker… Hhvm after 3.14.5 Fix from $2,3002017-02-17 MEDIUM 5.0 CVE-2014-6229 The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key … Hiphop Virtual Machine after 3.2.0 Fix from $1,6002014-12-28 HIGH 7.5 CVE-2014-6228 Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allow… Hiphop Virtual Machine after 3.2.0 Fix from $1,9502014-12-28 MEDIUM 5.0 CVE-2014-5386 The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the rand… Hiphop Virtual Machine after 3.2.0 Fix from $1,6002014-12-28 MEDIUM 5.0 CVE-2014-2209 Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-… Hiphop Virtual Machine after 3.0.1 Fix from $1,6002014-12-28