Записи facebook
132 опубликованных записей вендора facebook.
Профиль для исследователя
- Попали в KEV
- 2 · 1,5 %
- С эксплойтом
- 3 · 2,3 %
- Pre-auth RCE
- 28
- С записью об исправлении
- 35,6 %
- Медиана: публикация → KEV
- 1 дн.
Повторяющиеся классы
- CWE-125 Out-of-bounds Read10
- CWE-416 Use After Free9
- CWE-502 Deserialization of Untrusted Data8
- CWE-400 Uncontrolled Resource Consumption7
- CWE-122 Heap-based Buffer Overflow6
- CWE-787 Out-of-bounds Write6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
132 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2025-55182Готовый эксплойт | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Критическая10,0 | KEV | 99,8 % | 3 дек. 2025 г. |
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
50В плане | CVE-2025-55184Proof of concept | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.facebook · react · CWE-502 | Высокая7,5 | — | 66,9 % | 11 дек. 2025 г. |
48В плане | CVE-2008-0660Proof of concept | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and aurigma · image uploader activex control · CWE-119 | Критическая9,3 | — | 37,8 % | 7 февр. 2008 г. |
47В плане | CVE-2008-5711Готовый эксплойт | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary cfacebook · photouploader · CWE-119 | Критическая9,3 | — | 32,7 % | 24 дек. 2008 г. |
44В плане | CVE-2021-24040Proof of concept | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide maliciofacebook · parlai · CWE-502 | Критическая9,8 | — | 17,4 % | 10 сент. 2021 г. |
40В плане | CVE-2025-55183Proof of concept | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.vercel · next.js · CWE-502 | Средняя5,3 | — | 64,2 % | 11 дек. 2025 г. |
40В плане | CVE-2019-11929Эксплойта нет | Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading facebook · hhvm · CWE-119 | Критическая9,8 | — | 4,0 % | 2 окт. 2019 г. |
40В плане | CVE-2021-24036Эксплойта нет | Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with facebook · folly · CWE-122 | Критическая9,8 | — | 3,3 % | 22 июл. 2021 г. |
40В плане | CVE-2019-11930Эксплойта нет | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.facebook · hhvm · CWE-763 | Критическая9,8 | — | 3,2 % | 4 дек. 2019 г. |
40В плане | CVE-2018-6342Эксплойта нет | react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editofacebook · react-dev-utils · CWE-78 | Критическая9,8 | — | 2,8 % | 31 дек. 2018 г. |
40В плане | CVE-2020-1914Эксплойта нет | A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7ffacebook · hermes · CWE-670 | Критическая9,8 | — | 2,5 % | 8 окт. 2020 г. |
40В плане | CVE-2018-6331Эксплойта нет | Buck parser-cache command loads/saves state using Java serialized object.facebook · buck · CWE-502 | Критическая9,8 | — | 2,5 % | 31 дек. 2018 г. |
40В плане | CVE-2020-1896Эксплойта нет | A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.cfacebook · hermes · CWE-121 | Критическая9,8 | — | 2,4 % | 2 февр. 2021 г. |
40В плане | CVE-2018-6333Эксплойта нет | The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.facebook · nuclide · CWE-79 | Критическая9,8 | — | 2,3 % | 31 дек. 2018 г. |
40В плане | CVE-2016-6871Эксплойта нет | Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a facebook · hhvm · CWE-190 | Критическая9,8 | — | 2,3 % | 17 февр. 2017 г. |
40В плане | CVE-2019-11926Эксплойта нет | Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memoryfacebook · hhvm · CWE-119 | Критическая9,8 | — | 2,3 % | 6 сент. 2019 г. |
40В плане | CVE-2016-6875Эксплойта нет | Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm | Критическая9,8 | — | 2,2 % | 17 февр. 2017 г. |
40В плане | CVE-2016-6873Эксплойта нет | Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm | Критическая9,8 | — | 2,2 % | 17 февр. 2017 г. |
40В плане | CVE-2016-6872Эксплойта нет | Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm · CWE-190 | Критическая9,8 | — | 2,2 % | 17 февр. 2017 г. |
40В плане | CVE-2016-6870Эксплойта нет | Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allowsfacebook · hhvm · CWE-787 | Критическая9,8 | — | 2,2 % | 17 февр. 2017 г. |
40В плане | CVE-2019-11925Эксплойта нет | Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via facebook · hhvm · CWE-119 | Критическая9,8 | — | 2,1 % | 6 сент. 2019 г. |
40В плане | CVE-2019-11921Эксплойта нет | An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 wfacebook · proxygen · CWE-787 | Критическая9,8 | — | 2,1 % | 25 июл. 2019 г. |
40В плане | CVE-2016-6874Эксплойта нет | The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to rfacebook · hhvm | Критическая9,8 | — | 2,0 % | 17 февр. 2017 г. |
40В плане | CVE-2020-1911Эксплойта нет | A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prfacebook · hermes · CWE-843 | Критическая9,8 | — | 2,0 % | 3 сент. 2020 г. |
- CVE-2025-55182100Срочно
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %facebook · react3 дек. 2025 г.
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2025-5518450В плане
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.
ВысокаяCVSS 7,5Proof of conceptEPSS 67 %facebook · react11 дек. 2025 г.
- CVE-2008-066048В плане
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and
КритическаяCVSS 9,3Proof of conceptEPSS 38 %aurigma · image uploader activex control7 февр. 2008 г.
- CVE-2008-571147В плане
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary c
КритическаяCVSS 9,3Готовый эксплойтEPSS 33 %facebook · photouploader24 дек. 2008 г.
- CVE-2021-2404044В плане
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicio
КритическаяCVSS 9,8Proof of conceptEPSS 17 %facebook · parlai10 сент. 2021 г.
- CVE-2025-5518340В плане
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.
СредняяCVSS 5,3Proof of conceptEPSS 64 %vercel · next.js11 дек. 2025 г.
- CVE-2019-1192940В плане
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %facebook · hhvm2 окт. 2019 г.
- CVE-2021-2403640В плане
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %facebook · folly22 июл. 2021 г.
- CVE-2019-1193040В плане
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %facebook · hhvm4 дек. 2019 г.
- CVE-2018-634240В плане
react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an edito
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %facebook · react-dev-utils31 дек. 2018 г.
- CVE-2020-191440В плане
A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7f
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %facebook · hermes8 окт. 2020 г.
- CVE-2018-633140В плане
Buck parser-cache command loads/saves state using Java serialized object.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · buck31 дек. 2018 г.
- CVE-2020-189640В плане
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hermes2 февр. 2021 г.
- CVE-2018-633340В плане
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · nuclide31 дек. 2018 г.
- CVE-2016-687140В плане
Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm17 февр. 2017 г.
- CVE-2019-1192640В плане
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm6 сент. 2019 г.
- CVE-2016-687540В плане
Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm17 февр. 2017 г.
- CVE-2016-687340В плане
Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm17 февр. 2017 г.
- CVE-2016-687240В плане
Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm17 февр. 2017 г.
- CVE-2016-687040В плане
Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm17 февр. 2017 г.
- CVE-2019-1192540В плане
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm6 сент. 2019 г.
- CVE-2019-1192140В плане
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 w
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · proxygen25 июл. 2019 г.
- CVE-2016-687440В плане
The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to r
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hhvm17 февр. 2017 г.
- CVE-2020-191140В плане
A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes pr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · hermes3 сент. 2020 г.