CVE-2020-1919
- EPSS 0.36%
- Veröffentlicht 10.03.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:36
Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all vers...
CVE-2020-1921
- EPSS 0.59%
- Veröffentlicht 10.03.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:37
In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versi...
CVE-2020-1893
- EPSS 0.61%
- Veröffentlicht 03.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:33
Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions between 4.33.0 and 4.38.0 (inclusive), versio...
CVE-2020-1892
- EPSS 0.61%
- Veröffentlicht 03.03.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:33
Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to information leak and DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions betwe...
CVE-2020-1888
- EPSS 0.61%
- Veröffentlicht 03.03.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:33
Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions between 4.33.0 and 4.38.0 (inclusive),...
CVE-2016-1000109
- EPSS 1.59%
- Veröffentlicht 19.02.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 02:42:52
HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redi...
CVE-2016-1000005
- EPSS 0.53%
- Veröffentlicht 19.02.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 02:42:50
mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusi...
CVE-2016-1000004
- EPSS 0.19%
- Veröffentlicht 19.02.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 02:42:49
Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between ...
CVE-2019-11935
- EPSS 0.64%
- Veröffentlicht 04.12.2019 17:16:43
- Zuletzt bearbeitet 21.11.2024 04:22:00
Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as...
CVE-2019-11936
- EPSS 0.64%
- Veröffentlicht 04.12.2019 17:16:43
- Zuletzt bearbeitet 21.11.2024 04:22:01
Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.2...