Filters

Facebook HHVMHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in …

First published (updated )

Facebook HHVMPath Traversal

8.1
First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

Facebook HHVMUse After Free

First published (updated )

Facebook HHVMBuffer Overflow

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMThe fb_unserialize function did not impose a depth limit for nested deserialization. That meant a ma…

7.5
First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

Facebook HHVMIn the crypt function, we attempt to null terminate a buffer using the size of the input salt withou…

7.5
First published (updated )

Facebook HHVMIncorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second …

7.5
First published (updated )

Facebook HHVMxbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMIn-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking…

7.5
First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

Facebook HHVMInsufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds m…

8.1
First published (updated )

Facebook HHVMInsufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially …

7.5
First published (updated )

Facebook HHVMInsufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, poten…

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMHHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not …

First published (updated )

Facebook HHVMmcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to …

First published (updated )

Facebook HHVMInsufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode an…

First published (updated )

Facebook HHVMInsufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bou…

First published (updated )

Facebook HHVMVarious APC functions accept keys containing null bytes as input, leading to premature truncation of…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMAn invalid free in mb_detect_order can cause the application to crash or potentially result in remot…

First published (updated )

ubuntu/hhvmUse After Free

First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMHHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could…

7.5
First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Facebook HHVMThe function number_format is vulnerable to a heap overflow issue when its second argument ($dec_poi…

First published (updated )

Facebook HHVMThe implementations of streams for bz2 and php://output improperly implemented their readImpl functi…

First published (updated )

Facebook FollyBuffer Overflow

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMThe Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting thi…

8.1
First published (updated )

Facebook HHVMInput Validation

7.5
First published (updated )

Facebook HHVMInput Validation

First published (updated )

Facebook HHVMA potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cau…

First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMSelf recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact…

First published (updated )

Facebook HHVMInfinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impac…

First published (updated )

Facebook HHVMThe array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified …

First published (updated )

Facebook HHVMOut-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functio…

First published (updated )

Facebook HHVMInteger Overflow, Buffer Overflow

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203