Vulnerabilities > Proxygen Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-12-31 | CVE-2018-6347 | Improper Input Validation vulnerability in Proxygen Project Proxygen An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. | 7.5 |
2018-12-31 | CVE-2018-6346 | 7PK - Errors vulnerability in Proxygen Project Proxygen A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). | 7.5 |
2017-04-10 | CVE-2015-7265 | Improper Access Control vulnerability in Proxygen Project Proxygen Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks. | 7.5 |
2017-04-10 | CVE-2015-7264 | Injection vulnerability in Proxygen Project Proxygen The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks. | 9.8 |
2017-04-10 | CVE-2015-7263 | Improper Access Control vulnerability in Proxygen Project Proxygen The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value. | 7.5 |