Facebook

Hhvm

40 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Published 10.03.2021 16:15:14
  • Last modified 21.11.2024 05:11:36

Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all vers...

  • EPSS 0.59%
  • Published 10.03.2021 16:15:14
  • Last modified 21.11.2024 05:11:37

In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versi...

  • EPSS 0.61%
  • Published 03.03.2020 15:15:12
  • Last modified 21.11.2024 05:11:33

Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions between 4.33.0 and 4.38.0 (inclusive), versio...

  • EPSS 0.61%
  • Published 03.03.2020 15:15:11
  • Last modified 21.11.2024 05:11:33

Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to information leak and DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions betwe...

  • EPSS 0.61%
  • Published 03.03.2020 15:15:11
  • Last modified 21.11.2024 05:11:33

Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions between 4.33.0 and 4.38.0 (inclusive),...

Exploit
  • EPSS 1.59%
  • Published 19.02.2020 13:15:10
  • Last modified 21.11.2024 02:42:52

HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redi...

  • EPSS 0.53%
  • Published 19.02.2020 13:15:10
  • Last modified 21.11.2024 02:42:50

mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusi...

  • EPSS 0.19%
  • Published 19.02.2020 13:15:10
  • Last modified 21.11.2024 02:42:49

Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between ...

  • EPSS 0.64%
  • Published 04.12.2019 17:16:43
  • Last modified 21.11.2024 04:22:00

Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as...

  • EPSS 0.64%
  • Published 04.12.2019 17:16:43
  • Last modified 21.11.2024 04:22:01

Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.2...