Show filters
131 Total Results
Displaying 91-100 of 131
Sort by:
Attacker Value
Unknown
CVE-2019-3565
Disclosure Date: May 06, 2019 (last updated November 08, 2023)
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.05.06.00.
0
Attacker Value
Unknown
CVE-2019-3558
Disclosure Date: May 06, 2019 (last updated November 08, 2023)
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
0
Attacker Value
Unknown
CVE-2019-3559
Disclosure Date: May 06, 2019 (last updated November 08, 2023)
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
0
Attacker Value
Unknown
CVE-2019-3552
Disclosure Date: May 06, 2019 (last updated November 08, 2023)
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
0
Attacker Value
Unknown
CVE-2019-3563
Disclosure Date: April 29, 2019 (last updated November 27, 2024)
Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00
0
Attacker Value
Unknown
CVE-2019-3561
Disclosure Date: April 29, 2019 (last updated November 27, 2024)
Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).
0
Attacker Value
Unknown
CVE-2019-3560
Disclosure Date: April 29, 2019 (last updated November 08, 2023)
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
0
Attacker Value
Unknown
CVE-2018-6345
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be created with an invalid length, which can then interact poorly with other functions. This affects all supported versions of HHVM (3.30.1 and 3.27.5 and below).
0
Attacker Value
Unknown
CVE-2019-3554
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00
0
Attacker Value
Unknown
CVE-2019-3557
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
0