Перейти к содержимому
Noroxi

Записи facebook

132 опубликованных записей вендора facebook.

Профиль для исследователя

Попали в KEV
2 · 1,5 %
С эксплойтом
3 · 2,3 %
Pre-auth RCE
28
С записью об исправлении
35,6 %
Медиана: публикация → KEV
1 дн.

Записи по годам

  1. 17
  2. 18
  3. 19
  4. 20
  5. 21
  6. 22
  7. 23
  8. 24
  9. 25
  10. 26

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

132 записей
  • CVE-2025-55182
    100Срочно

    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    facebook · react3 дек. 2025 г.

  • CVE-2023-44487
    90Срочно

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.

  • CVE-2025-55184
    50В плане

    A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.

    ВысокаяCVSS 7,5Proof of conceptEPSS 67 %

    facebook · react11 дек. 2025 г.

  • CVE-2008-0660
    48В плане

    Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and

    КритическаяCVSS 9,3Proof of conceptEPSS 38 %

    aurigma · image uploader activex control7 февр. 2008 г.

  • CVE-2008-5711
    47В плане

    Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary c

    КритическаяCVSS 9,3Готовый эксплойтEPSS 33 %

    facebook · photouploader24 дек. 2008 г.

  • CVE-2021-24040
    44В плане

    Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicio

    КритическаяCVSS 9,8Proof of conceptEPSS 17 %

    facebook · parlai10 сент. 2021 г.

  • CVE-2025-55183
    40В плане

    An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.

    СредняяCVSS 5,3Proof of conceptEPSS 64 %

    vercel · next.js11 дек. 2025 г.

  • CVE-2019-11929
    40В плане

    Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    facebook · hhvm2 окт. 2019 г.

  • CVE-2021-24036
    40В плане

    Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    facebook · folly22 июл. 2021 г.

  • CVE-2019-11930
    40В плане

    An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    facebook · hhvm4 дек. 2019 г.

  • CVE-2018-6342
    40В плане

    react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an edito

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    facebook · react-dev-utils31 дек. 2018 г.

  • CVE-2020-1914
    40В плане

    A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7f

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    facebook · hermes8 окт. 2020 г.

  • CVE-2018-6331
    40В плане

    Buck parser-cache command loads/saves state using Java serialized object.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · buck31 дек. 2018 г.

  • CVE-2020-1896
    40В плане

    A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.c

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hermes2 февр. 2021 г.

  • CVE-2018-6333
    40В плане

    The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · nuclide31 дек. 2018 г.

  • CVE-2016-6871
    40В плане

    Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm17 февр. 2017 г.

  • CVE-2019-11926
    40В плане

    Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm6 сент. 2019 г.

  • CVE-2016-6875
    40В плане

    Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm17 февр. 2017 г.

  • CVE-2016-6873
    40В плане

    Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm17 февр. 2017 г.

  • CVE-2016-6872
    40В плане

    Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm17 февр. 2017 г.

  • CVE-2016-6870
    40В плане

    Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm17 февр. 2017 г.

  • CVE-2019-11925
    40В плане

    Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm6 сент. 2019 г.

  • CVE-2019-11921
    40В плане

    An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 w

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · proxygen25 июл. 2019 г.

  • CVE-2016-6874
    40В плане

    The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to r

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hhvm17 февр. 2017 г.

  • CVE-2020-1911
    40В плане

    A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes pr

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    facebook · hermes3 сент. 2020 г.