Facebook / Thrift
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-45863 | A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other unde… | MEDIUM | 5.3 | Sep 27, 2024 |
| CVE-2024-45773 | A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirab… | HIGH | 7.5 | Sep 27, 2024 |
| CVE-2021-24028 | An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects.… | CRITICAL | 9.8 | Apr 13, 2021 |
| CVE-2019-11939 | thrift: Resource exhaustion via containers sizes messages | HIGH | 7.5 | Mar 18, 2020 |
| CVE-2019-3553 | C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could… | HIGH | 7.5 | Mar 10, 2020 |
| CVE-2019-11938 | Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients coul… | HIGH | 7.5 | Mar 10, 2020 |
| CVE-2019-3565 | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result,… | HIGH | 7.5 | May 6, 2019 |
| CVE-2019-3564 | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short m… | HIGH | 7.5 | May 6, 2019 |
| CVE-2019-3559 | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short… | HIGH | 7.5 | May 6, 2019 |
| CVE-2019-3558 | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send sho… | HIGH | 7.5 | May 6, 2019 |
| CVE-2019-3552 | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients coul… | HIGH | 7.5 | May 6, 2019 |
Showing 1 to 11 of 11 CVEs