Show filters
131 Total Results
Displaying 91-100 of 131
Sort by:
Attacker Value
Unknown

CVE-2019-3565

Disclosure Date: May 06, 2019 (last updated November 08, 2023)
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.05.06.00.
Attacker Value
Unknown

CVE-2019-3558

Disclosure Date: May 06, 2019 (last updated November 08, 2023)
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
Attacker Value
Unknown

CVE-2019-3559

Disclosure Date: May 06, 2019 (last updated November 08, 2023)
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
Attacker Value
Unknown

CVE-2019-3552

Disclosure Date: May 06, 2019 (last updated November 08, 2023)
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
Attacker Value
Unknown

CVE-2019-3563

Disclosure Date: April 29, 2019 (last updated November 27, 2024)
Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00
Attacker Value
Unknown

CVE-2019-3561

Disclosure Date: April 29, 2019 (last updated November 27, 2024)
Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).
0
Attacker Value
Unknown

CVE-2019-3560

Disclosure Date: April 29, 2019 (last updated November 08, 2023)
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
Attacker Value
Unknown

CVE-2018-6345

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be created with an invalid length, which can then interact poorly with other functions. This affects all supported versions of HHVM (3.30.1 and 3.27.5 and below).
Attacker Value
Unknown

CVE-2019-3554

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00
0
Attacker Value
Unknown

CVE-2019-3557

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
0