Vulnerabilities > Proxygen Project

DATE CVE VULNERABILITY TITLE RISK
2018-12-31 CVE-2018-6347 Improper Input Validation vulnerability in Proxygen Project Proxygen
An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack.
network
low complexity
proxygen-project CWE-20
7.5
2018-12-31 CVE-2018-6346 7PK - Errors vulnerability in Proxygen Project Proxygen
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency).
network
low complexity
proxygen-project CWE-388
7.5
2017-04-10 CVE-2015-7265 Improper Access Control vulnerability in Proxygen Project Proxygen
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
network
low complexity
proxygen-project CWE-284
7.5
2017-04-10 CVE-2015-7264 Injection vulnerability in Proxygen Project Proxygen
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
network
low complexity
proxygen-project CWE-74
critical
9.8
2017-04-10 CVE-2015-7263 Improper Access Control vulnerability in Proxygen Project Proxygen
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.
network
low complexity
proxygen-project CWE-284
7.5