← Back

Facebook

facebook

127 CVEs • 32 products

Products (32)

Click to collapse
Toggle
Hhvm
hhvm
Hermes
hermes
Thrift
thrift
Proxygen
proxygen
React
react
Facebook
facebook
Zstandard
zstandard
Folly
folly
Fizz
fizz
Photouploader
photouploader
Wangle
wangle
Mcrouter
mcrouter
Instagram
instagram
Parlai
parlai
Buck
buck
Nuclide
nuclide
Gameroom
gameroom
Mvfst
mvfst
React Native
react-native
Messenger
messenger
Redex
redex
Lexical
lexical
Netconsd
netconsd
Tac Plus
tac_plus
React Devtools
react-devtools
Katran
katran
Below
below

CVEs (127)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Facebook
1Hhvm
Nov 21, 2024
Nov 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
1Facebook
1Hhvm
Jun 17, 2026
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all...Show more
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0.Show less
1Facebook
1Hhvm
Jun 17, 2026
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versi...Show more
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.Show less
1Facebook
1Hhvm
Jun 17, 2026
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions p...Show more
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.Show less
1Facebook
1Facebook For Woocommerce
Jun 17, 2026
Aug 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
1Facebook
1Facebook For Woocommerce
Jun 17, 2026
Aug 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
1Facebook
1Fizz
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above...Show more
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.Show less
1Facebook
1Zstandard
Jun 17, 2026
Jul 25, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
1Facebook
1Proxygen
Jun 17, 2026
Jul 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affe...Show more
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.Show less
1Facebook
1Hiphop Virtual Machine
Jun 17, 2026
Jul 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the ou...Show more
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would attempt to verify it by re-running scrypt_enc() with the same parameters. This could result in information disclosure, memory being overwriten or crashes of the HHVM process. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.Show less
1Facebook
1Hhvm
Jun 17, 2026
Jun 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure....Show more
HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.Show less
1Facebook
1Thrift
Jun 17, 2026
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take...Show more
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.05.06.00.Show less
1Facebook
1Thrift
Jun 17, 2026
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse,...Show more
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.Show less
1Facebook
1Thrift
Jun 17, 2026
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to pars...Show more
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.Show less
1Facebook
1Thrift
Jun 17, 2026
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to pa...Show more
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.Show less
1Facebook
1Thrift
Jun 17, 2026
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the se...Show more
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.Show less
1Facebook
1Wangle
Jun 17, 2026
Apr 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00
1Facebook
1Hhvm
Jun 17, 2026
Apr 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).
1Facebook
1Fizz
Jun 17, 2026
Apr 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
1Facebook
1Hhvm
Jun 17, 2026
Jan 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-o...Show more
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).Show less