Critical severity9.8NVD Advisory· Published Oct 2, 2019· Updated Jun 17, 2026
CVE-2019-11929
CVE-2019-11929
Description
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*range: <3.30.10
- cpe:2.3:a:facebook:hhvm:4.19.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.19.1:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.20.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.20.1:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.20.2:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.21.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.22.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.23.0:*:*:*:*:*:*:*
- (no CPE)range: <3.30.10, 4.0.0-4.8.5, 4.9.0-4.18.2, 4.19.0-4.23.0
- (no CPE)range: 4.24.0
Patches
Vulnerability mechanics
References
3- github.com/facebook/hhvm/commit/dbeb9a56a638e3fdcef8b691c2a2967132dae692nvdPatchThird Party Advisory
- hhvm.com/blog/2019/09/25/security-update.htmlnvdVendor Advisory
- www.facebook.com/security/advisories/cve-2019-11929nvdThird Party Advisory
News mentions
0No linked articles in our index yet.