CVE-2019-3570
- EPSS 0.61%
- Veröffentlicht 18.07.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:42:11
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a cont...
CVE-2014-9714
- EPSS 0.52%
- Veröffentlicht 13.04.2015 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value...
- EPSS 0.25%
- Veröffentlicht 28.12.2014 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for termination, which allows remote attackers to obtain sensitive information by le...
CVE-2014-6228
- EPSS 0.46%
- Veröffentlicht 28.12.2014 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified othe...
- EPSS 0.24%
- Veröffentlicht 28.12.2014 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection me...
- EPSS 0.3%
- Veröffentlicht 28.12.2014 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group...
CVE-2014-2208
- EPSS 0.7%
- Veröffentlicht 28.12.2014 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character ...