Facebook / HHVM
40 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-36937 | HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnera… | CRITICAL | 9.8 | May 10, 2023 |
| CVE-2019-3556 | HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to outp… | HIGH | 8.1 | Oct 26, 2021 |
| CVE-2021-24036 | Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of… | CRITICAL | 9.8 | Jul 23, 2021 |
| CVE-2020-1900 | When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. O… | CRITICAL | 9.8 | Mar 11, 2021 |
| CVE-2020-1899 | The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addr… | HIGH | 7.5 | Mar 11, 2021 |
| CVE-2020-1898 | The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserialization to… | HIGH | 7.5 | Mar 11, 2021 |
| CVE-2021-24025 | Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading t… | CRITICAL | 9.8 | Mar 10, 2021 |
| CVE-2020-1921 | In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer. This iss… | HIGH | 7.5 | Mar 10, 2021 |
| CVE-2020-1919 | Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This is… | HIGH | 7.5 | Mar 10, 2021 |
| CVE-2020-1918 | In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory prior to the in-memory… | HIGH | 7.5 | Mar 10, 2021 |
| CVE-2020-1917 | xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its standard appen… | CRITICAL | 9.8 | Mar 10, 2021 |
| CVE-2020-1916 | An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This iss… | CRITICAL | 9.8 | Mar 10, 2021 |
| CVE-2020-1893 | Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.4… | HIGH | 7.5 | Mar 3, 2020 |
| CVE-2020-1892 | Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to information leak and DOS. Thi… | HIGH | 8.1 | Mar 3, 2020 |
| CVE-2020-1888 | Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4.44… | HIGH | 7.5 | Mar 3, 2020 |
| CVE-2016-1000109 | HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted cli… | MEDIUM | 5.3 | Feb 19, 2020 |
| CVE-2016-1000005 | mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This… | CRITICAL | 9.8 | Feb 19, 2020 |
| CVE-2016-1000004 | Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions pr… | CRITICAL | 9.8 | Feb 19, 2020 |
| CVE-2019-11936 | Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12,… | CRITICAL | 9.8 | Dec 4, 2019 |
| CVE-2019-11935 | Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.… | CRITICAL | 9.8 | Dec 4, 2019 |
| CVE-2019-11930 | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to… | CRITICAL | 9.8 | Dec 4, 2019 |
| CVE-2016-1000006 | hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions. | CRITICAL | 9.8 | Nov 19, 2019 |
| CVE-2019-11929 | Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code exec… | CRITICAL | 9.8 | Oct 2, 2019 |
| CVE-2019-11926 | Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously… | CRITICAL | 9.8 | Sep 6, 2019 |
| CVE-2019-11925 | Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously const… | CRITICAL | 9.8 | Sep 6, 2019 |
Showing 1 to 25 of 40 CVEs