Vulnerabilities > Facebook > High

DATE CVE VULNERABILITY TITLE RISK
2019-05-06 CVE-2019-3552 Improper Handling of Exceptional Conditions vulnerability in Facebook Thrift
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.
network
low complexity
facebook CWE-755
7.5
2019-04-29 CVE-2019-3560 Infinite Loop vulnerability in Facebook Fizz
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input.
network
low complexity
facebook CWE-835
7.5
2018-12-31 CVE-2018-6343 Improper Input Validation vulnerability in Facebook Proxygen 2018.10.29.00/2018.11.05.00/2018.11.12.00
Proxygen fails to validate that a secondary auth manager is set before dereferencing it.
network
low complexity
facebook CWE-20
7.5
2018-12-31 CVE-2018-6340 Out-of-bounds Read vulnerability in Facebook Hhvm
The Memcache::getextendedstats function can be used to trigger an out-of-bounds read.
network
high complexity
facebook CWE-125
8.1
2018-12-31 CVE-2018-6337 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Facebook Folly and Hhvm
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called.
network
low complexity
facebook CWE-119
7.5
2018-12-31 CVE-2018-6335 Improper Input Validation vulnerability in Facebook Hhvm
A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data.
network
low complexity
facebook CWE-20
7.5