7.5

CVE-2019-3569

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

Data is provided by the National Vulnerability Database (NVD)
FacebookHhvm Version <= 3.30.5
FacebookHhvm Version4.0.0
FacebookHhvm Version4.0.1
FacebookHhvm Version4.0.2
FacebookHhvm Version4.0.3
FacebookHhvm Version4.0.4
FacebookHhvm Version4.1.0
FacebookHhvm Version4.2.0
FacebookHhvm Version4.3.0
FacebookHhvm Version4.4.0
FacebookHhvm Version4.5.0
FacebookHhvm Version4.6.0
FacebookHhvm Version4.7.0
FacebookHhvm Version4.8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.37% 0.58
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.