Filters

ZDNetHijacked Facebook Pages are pushing fake AI services to steal your data

First published (updated )
News
ZDNet

The RegisterMeta accused of snarfing people's Snapchat data via traffic decryption

First published (updated )

Facebook Meta Spark StudioPrior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of …

7.8
EPSS
0.06%
First published (updated )

Facebook KatranKatran could disclose non-initialized kernel memory as part of an IP header. The issue was present f…

7.5
First published (updated )

npm/react-devtools-coreThe React Developer Tools extension registers a message listener with window.addEventListener('messa…

EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache Tomcat- Rapid Reset HTTP/2 vulnerability

First published (updated )

Facebook Tac PlusInput Validation

First published (updated )

Facebook HermesAn error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a5949…

First published (updated )

Facebook HermesUse After Free

First published (updated )

Facebook HermesCVE-2023-25933

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HermesAn error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a…

First published (updated )

Facebook HermesUse After Free

First published (updated )

Facebook NetconsdInteger Overflow

First published (updated )

Facebook HermesUse After Free

7.5
First published (updated )

Facebook HermesNull Pointer Dereference

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook FizzThere is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be tr…

7.5
First published (updated )

Facebook HHVMHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in …

First published (updated )

Facebook LexicalXSS

First published (updated )

Facebook ZstandardBuffer Overflow

7.5
First published (updated )

Facebook RedexDexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HermesInteger Overflow

First published (updated )

Facebook HermesAn out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d…

First published (updated )

Facebook HermesAn integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d1…

First published (updated )

Facebook HermesIt was possible to trigger an infinite recursion condition in the error handler when Hermes executed…

7.5
First published (updated )

Facebook InstagramInstagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly repr…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook MessengerThe Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interfa…

First published (updated )

Facebook HermesBy passing invalid javascript code where await and yield were called upon non-async and non-generato…

First published (updated )

Facebook HermesA type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Face…

First published (updated )

Facebook HHVMPath Traversal

8.1
First published (updated )

Facebook ParlaiDeserialization of Untrusted Data in parlai

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook ParlaiDue to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML c…

First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

Facebook HermesUse After Free

First published (updated )

Facebook React-nativeA regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cau…

7.5
First published (updated )

Facebook ThriftCVE-2021-24028

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook FacebookCSRF

8.8
First published (updated )

Facebook FacebookCVE-2021-24217

8.1
First published (updated )

Facebook MvfstA packet of death scenario is possible in mvfst via a specially crafted message during a QUIC sessio…

7.5
First published (updated )

Facebook HHVMUse After Free

First published (updated )

Facebook HHVMBuffer Overflow

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMThe fb_unserialize function did not impose a depth limit for nested deserialization. That meant a ma…

7.5
First published (updated )

CVE-2021-24030The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote argumen…

First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

Facebook HHVMIn the crypt function, we attempt to null terminate a buffer using the size of the input salt withou…

7.5
First published (updated )

Facebook HHVMIncorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second …

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMxbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to…

First published (updated )

Facebook HHVMIn-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking…

7.5
First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

IBM Planning AnalyticsOS Command Injection, Command Injection

First published (updated )

Facebook ZstandardIn the Zstandard command-line utility prior to v1.4.1, output files were created with default permis…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203