Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown
CVE-2022-27810
Disclosure Date: October 06, 2022 (last updated October 08, 2023)
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.
0
Attacker Value
Unknown
CVE-2021-24044
Disclosure Date: January 15, 2022 (last updated October 07, 2023)
By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.
0
Attacker Value
Unknown
CVE-2021-24045
Disclosure Date: December 13, 2021 (last updated October 07, 2023)
A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
0
Attacker Value
Unknown
CVE-2021-24037
Disclosure Date: June 15, 2021 (last updated November 28, 2024)
A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
0
Attacker Value
Unknown
CVE-2021-23909
Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code execution.
0
Attacker Value
Unknown
CVE-2021-23910
Disclosure Date: May 13, 2021 (last updated November 28, 2024)
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is an out-of-bounds array access in RemoteDiagnosisApp.
0
Attacker Value
Unknown
CVE-2020-1896
Disclosure Date: February 02, 2021 (last updated November 28, 2024)
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.com/facebook/hermes/commit/86543ac47e59c522976b5632b8bf9a2a4583c7d2) allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
0
Attacker Value
Unknown
CVE-2019-19557
Disclosure Date: November 16, 2020 (last updated November 28, 2024)
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
0
Attacker Value
Unknown
CVE-2019-19562
Disclosure Date: November 16, 2020 (last updated November 28, 2024)
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.
0
Attacker Value
Unknown
CVE-2019-19560
Disclosure Date: November 16, 2020 (last updated November 28, 2024)
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.
0