Skip to content
Noroxi

facebook records

132 published records for vendor facebook.

Researcher profile

Entered KEV
2 · 1.5%
Weaponized
3 · 2.3%
Pre-auth RCE
28
With a fix record
35.6%
Median publish → KEV
1 days

All records

132 records
  • A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    facebook · reactDec 3, 2025

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.

    HighCVSS 7.5Proof of conceptEPSS 67%

    facebook · reactDec 11, 2025

  • Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and

    CriticalCVSS 9.3Proof of conceptEPSS 38%

    aurigma · image uploader activex controlFeb 7, 2008

  • Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary c

    CriticalCVSS 9.3WeaponizedEPSS 33%

    facebook · photouploaderDec 24, 2008

  • Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicio

    CriticalCVSS 9.8Proof of conceptEPSS 17%

    facebook · parlaiSep 10, 2021

  • An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.

    MediumCVSS 5.3Proof of conceptEPSS 64%

    vercel · next.jsDec 11, 2025

  • Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading

    CriticalCVSS 9.8No exploitEPSS 4%

    facebook · hhvmOct 2, 2019

  • Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with

    CriticalCVSS 9.8No exploitEPSS 3%

    facebook · follyJul 22, 2021

  • An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.

    CriticalCVSS 9.8No exploitEPSS 3%

    facebook · hhvmDec 4, 2019

  • react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an edito

    CriticalCVSS 9.8No exploitEPSS 3%

    facebook · react-dev-utilsDec 31, 2018

  • A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7f

    CriticalCVSS 9.8No exploitEPSS 3%

    facebook · hermesOct 8, 2020

  • Buck parser-cache command loads/saves state using Java serialized object.

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · buckDec 31, 2018

  • A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.c

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hermesFeb 2, 2021

  • The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · nuclideDec 31, 2018

  • Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmFeb 17, 2017

  • Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmSep 6, 2019

  • Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmFeb 17, 2017

  • Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmFeb 17, 2017

  • Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmFeb 17, 2017

  • Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmFeb 17, 2017

  • Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmSep 6, 2019

  • An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 w

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · proxygenJul 25, 2019

  • The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to r

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hhvmFeb 17, 2017

  • A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes pr

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · hermesSep 3, 2020