Facebook

Hiphop Virtual Machine

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.61%
  • Veröffentlicht 18.07.2019 16:15:12
  • Zuletzt bearbeitet 21.11.2024 04:42:11

Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a cont...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 13.04.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value...

  • EPSS 0.25%
  • Veröffentlicht 28.12.2014 15:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for termination, which allows remote attackers to obtain sensitive information by le...

  • EPSS 0.46%
  • Veröffentlicht 28.12.2014 15:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified othe...

  • EPSS 0.24%
  • Veröffentlicht 28.12.2014 15:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection me...

  • EPSS 0.3%
  • Veröffentlicht 28.12.2014 15:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group...

  • EPSS 0.7%
  • Veröffentlicht 28.12.2014 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character ...