Filters

Facebook Tac PlusInput Validation

First published (updated )

Facebook HermesAn error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a5949…

First published (updated )

Facebook HermesUse After Free

First published (updated )

Facebook HermesCVE-2023-25933

First published (updated )

Facebook HermesAn error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HermesUse After Free

First published (updated )

Facebook NetconsdInteger Overflow

First published (updated )

Facebook HHVMHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in …

First published (updated )

Facebook RedexDexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound…

First published (updated )

Facebook HermesInteger Overflow

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HermesAn out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d…

First published (updated )

Facebook HermesAn integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d1…

First published (updated )

Facebook HermesBy passing invalid javascript code where await and yield were called upon non-async and non-generato…

First published (updated )

Facebook HermesA type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Face…

First published (updated )

Facebook ParlaiDue to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML c…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMInteger Overflow

First published (updated )

Facebook HermesUse After Free

First published (updated )

Facebook ThriftCVE-2021-24028

First published (updated )

Facebook HHVMUse After Free

First published (updated )

CVE-2021-24030The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote argumen…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HHVMInteger Overflow

First published (updated )

Facebook HHVMxbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to…

First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

IBM Planning AnalyticsOS Command Injection, Command Injection

First published (updated )

Facebook HermesA stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c52297…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HermesA logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to co…

First published (updated )

Facebook HermesA type confusion vulnerability when resolving properties of JavaScript objects with specially-crafte…

First published (updated )

Facebook ProxygenUse After Free

First published (updated )

Facebook HHVMmcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to …

First published (updated )

Facebook HHVMInsufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode an…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook ProxygenUse After Free

First published (updated )

Facebook FollyImproper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This…

First published (updated )

Facebook HHVMInsufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bou…

First published (updated )

Facebook HHVMVarious APC functions accept keys containing null bytes as input, leading to premature truncation of…

First published (updated )

Facebook HHVMAn invalid free in mb_detect_order can cause the application to crash or potentially result in remot…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

ubuntu/hhvmUse After Free

First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Facebook ProxygenAn out of bounds write is possible via a specially crafted packet in certain configurations of Proxy…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook HipHop Virtual MachineCall to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted …

First published (updated )

Facebook WangleWangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a …

First published (updated )

Facebook HHVMBuffer Overflow

First published (updated )

Facebook HHVMThe function number_format is vulnerable to a heap overflow issue when its second argument ($dec_poi…

First published (updated )

Facebook HHVMThe implementations of streams for bz2 and php://output improperly implemented their readImpl functi…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Facebook BuckBuck parser-cache command loads/saves state using Java serialized object. If the state information i…

First published (updated )

Facebook NuclideInput Validation, XSS

First published (updated )

Facebook react-dev-utilsOS Command Injection, CSRF

First published (updated )

Facebook HHVMInput Validation

First published (updated )

Facebook HHVMInteger Overflow

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203