facebook records
132 published records for vendor facebook.
Researcher profile
- Entered KEV
- 2 · 1.5%
- Weaponized
- 3 · 2.3%
- Pre-auth RCE
- 28
- With a fix record
- 35.6%
- Median publish → KEV
- 1 days
Recurring classes
- CWE-125 Out-of-bounds Read10
- CWE-416 Use After Free9
- CWE-502 Deserialization of Untrusted Data8
- CWE-400 Uncontrolled Resource Consumption7
- CWE-122 Heap-based Buffer Overflow6
- CWE-787 Out-of-bounds Write6
The weakness classes this vendor ships most often: where to look.
CWEAll records
132 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2025-55182Weaponized | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Critical10.0 | KEV | 99.8% | Dec 3, 2025 |
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
50Plan | CVE-2025-55184Proof of concept | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.facebook · react · CWE-502 | High7.5 | — | 66.9% | Dec 11, 2025 |
48Plan | CVE-2008-0660Proof of concept | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and aurigma · image uploader activex control · CWE-119 | Critical9.3 | — | 37.8% | Feb 7, 2008 |
47Plan | CVE-2008-5711Weaponized | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary cfacebook · photouploader · CWE-119 | Critical9.3 | — | 32.7% | Dec 24, 2008 |
44Plan | CVE-2021-24040Proof of concept | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide maliciofacebook · parlai · CWE-502 | Critical9.8 | — | 17.4% | Sep 10, 2021 |
40Plan | CVE-2025-55183Proof of concept | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.vercel · next.js · CWE-502 | Medium5.3 | — | 64.2% | Dec 11, 2025 |
40Plan | CVE-2019-11929No exploit | Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading facebook · hhvm · CWE-119 | Critical9.8 | — | 4.0% | Oct 2, 2019 |
40Plan | CVE-2021-24036No exploit | Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with facebook · folly · CWE-122 | Critical9.8 | — | 3.3% | Jul 22, 2021 |
40Plan | CVE-2019-11930No exploit | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.facebook · hhvm · CWE-763 | Critical9.8 | — | 3.2% | Dec 4, 2019 |
40Plan | CVE-2018-6342No exploit | react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editofacebook · react-dev-utils · CWE-78 | Critical9.8 | — | 2.8% | Dec 31, 2018 |
40Plan | CVE-2020-1914No exploit | A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7ffacebook · hermes · CWE-670 | Critical9.8 | — | 2.5% | Oct 8, 2020 |
40Plan | CVE-2018-6331No exploit | Buck parser-cache command loads/saves state using Java serialized object.facebook · buck · CWE-502 | Critical9.8 | — | 2.5% | Dec 31, 2018 |
40Plan | CVE-2020-1896No exploit | A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.cfacebook · hermes · CWE-121 | Critical9.8 | — | 2.4% | Feb 2, 2021 |
40Plan | CVE-2018-6333No exploit | The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.facebook · nuclide · CWE-79 | Critical9.8 | — | 2.3% | Dec 31, 2018 |
40Plan | CVE-2016-6871No exploit | Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a facebook · hhvm · CWE-190 | Critical9.8 | — | 2.3% | Feb 17, 2017 |
40Plan | CVE-2019-11926No exploit | Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memoryfacebook · hhvm · CWE-119 | Critical9.8 | — | 2.3% | Sep 6, 2019 |
40Plan | CVE-2016-6875No exploit | Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm | Critical9.8 | — | 2.2% | Feb 17, 2017 |
40Plan | CVE-2016-6873No exploit | Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm | Critical9.8 | — | 2.2% | Feb 17, 2017 |
40Plan | CVE-2016-6872No exploit | Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm · CWE-190 | Critical9.8 | — | 2.2% | Feb 17, 2017 |
40Plan | CVE-2016-6870No exploit | Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allowsfacebook · hhvm · CWE-787 | Critical9.8 | — | 2.2% | Feb 17, 2017 |
40Plan | CVE-2019-11925No exploit | Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via facebook · hhvm · CWE-119 | Critical9.8 | — | 2.1% | Sep 6, 2019 |
40Plan | CVE-2019-11921No exploit | An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 wfacebook · proxygen · CWE-787 | Critical9.8 | — | 2.1% | Jul 25, 2019 |
40Plan | CVE-2016-6874No exploit | The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to rfacebook · hhvm | Critical9.8 | — | 2.0% | Feb 17, 2017 |
40Plan | CVE-2020-1911No exploit | A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prfacebook · hermes · CWE-843 | Critical9.8 | — | 2.0% | Sep 3, 2020 |
- CVE-2025-55182100Now
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
CriticalCVSS 10.0KEVWeaponizedEPSS 100%facebook · reactDec 3, 2025
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2025-5518450Plan
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.
HighCVSS 7.5Proof of conceptEPSS 67%facebook · reactDec 11, 2025
- CVE-2008-066048Plan
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and
CriticalCVSS 9.3Proof of conceptEPSS 38%aurigma · image uploader activex controlFeb 7, 2008
- CVE-2008-571147Plan
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary c
CriticalCVSS 9.3WeaponizedEPSS 33%facebook · photouploaderDec 24, 2008
- CVE-2021-2404044Plan
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicio
CriticalCVSS 9.8Proof of conceptEPSS 17%facebook · parlaiSep 10, 2021
- CVE-2025-5518340Plan
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.
MediumCVSS 5.3Proof of conceptEPSS 64%vercel · next.jsDec 11, 2025
- CVE-2019-1192940Plan
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading
CriticalCVSS 9.8No exploitEPSS 4%facebook · hhvmOct 2, 2019
- CVE-2021-2403640Plan
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with
CriticalCVSS 9.8No exploitEPSS 3%facebook · follyJul 22, 2021
- CVE-2019-1193040Plan
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.
CriticalCVSS 9.8No exploitEPSS 3%facebook · hhvmDec 4, 2019
- CVE-2018-634240Plan
react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an edito
CriticalCVSS 9.8No exploitEPSS 3%facebook · react-dev-utilsDec 31, 2018
- CVE-2020-191440Plan
A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7f
CriticalCVSS 9.8No exploitEPSS 3%facebook · hermesOct 8, 2020
- CVE-2018-633140Plan
Buck parser-cache command loads/saves state using Java serialized object.
CriticalCVSS 9.8No exploitEPSS 2%facebook · buckDec 31, 2018
- CVE-2020-189640Plan
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.c
CriticalCVSS 9.8No exploitEPSS 2%facebook · hermesFeb 2, 2021
- CVE-2018-633340Plan
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.
CriticalCVSS 9.8No exploitEPSS 2%facebook · nuclideDec 31, 2018
- CVE-2016-687140Plan
Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmFeb 17, 2017
- CVE-2019-1192640Plan
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmSep 6, 2019
- CVE-2016-687540Plan
Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmFeb 17, 2017
- CVE-2016-687340Plan
Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmFeb 17, 2017
- CVE-2016-687240Plan
Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmFeb 17, 2017
- CVE-2016-687040Plan
Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmFeb 17, 2017
- CVE-2019-1192540Plan
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmSep 6, 2019
- CVE-2019-1192140Plan
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 w
CriticalCVSS 9.8No exploitEPSS 2%facebook · proxygenJul 25, 2019
- CVE-2016-687440Plan
The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to r
CriticalCVSS 9.8No exploitEPSS 2%facebook · hhvmFeb 17, 2017
- CVE-2020-191140Plan
A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes pr
CriticalCVSS 9.8No exploitEPSS 2%facebook · hermesSep 3, 2020