VYPR

HHVM

by HHVM

Source repositories

CVEs (28)

  • CVE-2019-11935CriDec 4, 2019
    risk 0.00cvss 9.8epss 0.01

    Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0,…

  • CVE-2019-11930CriDec 4, 2019
    risk 0.00cvss 9.8epss 0.03

    An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0,…

  • CVE-2019-3570CriJul 18, 2019
    risk 0.00cvss 9.8epss 0.02

    Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would…

  • CVE-2019-3561CriApr 29, 2019
    risk 0.00cvss 9.8epss 0.02

    Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).

  • CVE-2019-3557CriJan 15, 2019
    risk 0.00cvss 9.8epss 0.02

    The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The…

  • CVE-2018-6345CriJan 15, 2019
    risk 0.00cvss 9.8epss 0.02

    The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be created with an invalid length, which can then interact poorly with other…

  • CVE-2018-6340HigDec 31, 2018
    risk 0.00cvss 8.1epss 0.01

    The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).

  • CVE-2018-6334CriDec 31, 2018
    risk 0.00cvss 9.8epss 0.02

    Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and…

Page 2 of 2