Show filters
131 Total Results
Displaying 81-90 of 131
Sort by:
Attacker Value
Unknown
CVE-2019-15840
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2019-11924
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.
0
Attacker Value
Unknown
CVE-2019-11923
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.
0
Attacker Value
Unknown
CVE-2019-11940
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00.
0
Attacker Value
Unknown
CVE-2019-11937
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.
0
Attacker Value
Unknown
CVE-2019-11921
Disclosure Date: July 25, 2019 (last updated November 27, 2024)
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.
0
Attacker Value
Unknown
CVE-2019-11922
Disclosure Date: July 25, 2019 (last updated November 27, 2024)
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
0
Attacker Value
Unknown
CVE-2019-3570
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would attempt to verify it by re-running scrypt_enc() with the same parameters. This could result in information disclosure, memory being overwriten or crashes of the HHVM process. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
0
Attacker Value
Unknown
CVE-2019-3569
Disclosure Date: June 26, 2019 (last updated November 27, 2024)
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
0
Attacker Value
Unknown
CVE-2019-3564
Disclosure Date: May 06, 2019 (last updated November 08, 2023)
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
0