Where
-Infinity
0

Facebook HHVMHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in …

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMPath Traversal

Risk 60
Severity
8.1
First published (updated )

Facebook HHVMUse After Free

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMBuffer Overflow

Risk 43
Severity
7.5
First published (updated )

Facebook HHVMThe fb_unserialize function did not impose a depth limit for nested deserialization. That meant a ma…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Facebook HHVMInteger Overflow

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMIn the crypt function, we attempt to null terminate a buffer using the size of the input salt withou…

Risk 43
Severity
7.5
First published (updated )

Facebook HHVMIncorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second …

Risk 43
Severity
7.5
First published (updated )

Facebook HHVMxbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to…

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMIn-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Facebook HHVMInteger Overflow

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMInsufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds m…

Risk 59
Severity
8.1
First published (updated )

Facebook HHVMInsufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially …

Risk 43
Severity
7.5
First published (updated )

Facebook HHVMInsufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, poten…

Risk 43
Severity
7.5
First published (updated )

Facebook HHVMHHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not …

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Facebook HHVMmcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to …

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMInsufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode an…

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMInsufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bou…

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMVarious APC functions accept keys containing null bytes as input, leading to premature truncation of…

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMAn invalid free in mb_detect_order can cause the application to crash or potentially result in remot…

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Facebook HHVMBuffer Overflow

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMBuffer Overflow

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMBuffer Overflow

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMHHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could…

Risk 43
Severity
7.5
First published (updated )

Facebook HHVMBuffer Overflow

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Facebook HHVMThe function number_format is vulnerable to a heap overflow issue when its second argument ($dec_poi…

Risk 86
Severity
9.8
First published (updated )

Facebook HHVMThe implementations of streams for bz2 and php://output improperly implemented their readImpl functi…

Risk 86
Severity
9.8
First published (updated )

Facebook FollyBuffer Overflow

Risk 43
Severity
7.5
First published (updated )

Facebook HHVMThe Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting thi…

Risk 75
Severity
8.1
First published (updated )

Facebook HHVMInput Validation

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203