facebook kayıtları
facebook üreticisine ait 132 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %1,5
- Silahlaştırılmış
- 3 · %2,3
- Pre-auth RCE
- 28
- Düzeltme kaydı olan
- %35,6
- Yayından KEV’e ortanca
- 1 gün
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read10
- CWE-416 Use After Free9
- CWE-502 Deserialization of Untrusted Data8
- CWE-400 Uncontrolled Resource Consumption7
- CWE-122 Heap-based Buffer Overflow6
- CWE-787 Out-of-bounds Write6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
132 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2025-55182Silahlaştırılmış | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Kritik10,0 | KEV | %99,8 | 3 Ara 2025 |
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
50Planlayın | CVE-2025-55184Kavram kanıtı | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.facebook · react · CWE-502 | Yüksek7,5 | — | %66,9 | 11 Ara 2025 |
48Planlayın | CVE-2008-0660Kavram kanıtı | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and aurigma · image uploader activex control · CWE-119 | Kritik9,3 | — | %37,8 | 7 Şub 2008 |
47Planlayın | CVE-2008-5711Silahlaştırılmış | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary cfacebook · photouploader · CWE-119 | Kritik9,3 | — | %32,7 | 24 Ara 2008 |
44Planlayın | CVE-2021-24040Kavram kanıtı | Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide maliciofacebook · parlai · CWE-502 | Kritik9,8 | — | %17,4 | 10 Eyl 2021 |
40Planlayın | CVE-2025-55183Kavram kanıtı | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.vercel · next.js · CWE-502 | Orta5,3 | — | %64,2 | 11 Ara 2025 |
40Planlayın | CVE-2019-11929İstismar yok | Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading facebook · hhvm · CWE-119 | Kritik9,8 | — | %4,0 | 2 Eki 2019 |
40Planlayın | CVE-2021-24036İstismar yok | Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with facebook · folly · CWE-122 | Kritik9,8 | — | %3,3 | 22 Tem 2021 |
40Planlayın | CVE-2019-11930İstismar yok | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.facebook · hhvm · CWE-763 | Kritik9,8 | — | %3,2 | 4 Ara 2019 |
40Planlayın | CVE-2018-6342İstismar yok | react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editofacebook · react-dev-utils · CWE-78 | Kritik9,8 | — | %2,8 | 31 Ara 2018 |
40Planlayın | CVE-2020-1914İstismar yok | A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7ffacebook · hermes · CWE-670 | Kritik9,8 | — | %2,5 | 8 Eki 2020 |
40Planlayın | CVE-2018-6331İstismar yok | Buck parser-cache command loads/saves state using Java serialized object.facebook · buck · CWE-502 | Kritik9,8 | — | %2,5 | 31 Ara 2018 |
40Planlayın | CVE-2020-1896İstismar yok | A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.cfacebook · hermes · CWE-121 | Kritik9,8 | — | %2,4 | 2 Şub 2021 |
40Planlayın | CVE-2018-6333İstismar yok | The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.facebook · nuclide · CWE-79 | Kritik9,8 | — | %2,3 | 31 Ara 2018 |
40Planlayın | CVE-2016-6871İstismar yok | Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a facebook · hhvm · CWE-190 | Kritik9,8 | — | %2,3 | 17 Şub 2017 |
40Planlayın | CVE-2019-11926İstismar yok | Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memoryfacebook · hhvm · CWE-119 | Kritik9,8 | — | %2,3 | 6 Eyl 2019 |
40Planlayın | CVE-2016-6875İstismar yok | Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm | Kritik9,8 | — | %2,2 | 17 Şub 2017 |
40Planlayın | CVE-2016-6873İstismar yok | Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm | Kritik9,8 | — | %2,2 | 17 Şub 2017 |
40Planlayın | CVE-2016-6872İstismar yok | Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.facebook · hhvm · CWE-190 | Kritik9,8 | — | %2,2 | 17 Şub 2017 |
40Planlayın | CVE-2016-6870İstismar yok | Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allowsfacebook · hhvm · CWE-787 | Kritik9,8 | — | %2,2 | 17 Şub 2017 |
40Planlayın | CVE-2019-11925İstismar yok | Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via facebook · hhvm · CWE-119 | Kritik9,8 | — | %2,1 | 6 Eyl 2019 |
40Planlayın | CVE-2019-11921İstismar yok | An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 wfacebook · proxygen · CWE-787 | Kritik9,8 | — | %2,1 | 25 Tem 2019 |
40Planlayın | CVE-2016-6874İstismar yok | The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to rfacebook · hhvm | Kritik9,8 | — | %2,0 | 17 Şub 2017 |
40Planlayın | CVE-2020-1911İstismar yok | A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prfacebook · hermes · CWE-843 | Kritik9,8 | — | %2,0 | 3 Eyl 2020 |
- CVE-2025-55182100Hemen
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100facebook · react3 Ara 2025
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2025-5518450Planlayın
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.
YüksekCVSS 7,5Kavram kanıtıEPSS %67facebook · react11 Ara 2025
- CVE-2008-066048Planlayın
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and
KritikCVSS 9,3Kavram kanıtıEPSS %38aurigma · image uploader activex control7 Şub 2008
- CVE-2008-571147Planlayın
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary c
KritikCVSS 9,3SilahlaştırılmışEPSS %33facebook · photouploader24 Ara 2008
- CVE-2021-2404044Planlayın
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicio
KritikCVSS 9,8Kavram kanıtıEPSS %17facebook · parlai10 Eyl 2021
- CVE-2025-5518340Planlayın
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.
OrtaCVSS 5,3Kavram kanıtıEPSS %64vercel · next.js11 Ara 2025
- CVE-2019-1192940Planlayın
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading
KritikCVSS 9,8İstismar yokEPSS %4facebook · hhvm2 Eki 2019
- CVE-2021-2403640Planlayın
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with
KritikCVSS 9,8İstismar yokEPSS %3facebook · folly22 Tem 2021
- CVE-2019-1193040Planlayın
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.
KritikCVSS 9,8İstismar yokEPSS %3facebook · hhvm4 Ara 2019
- CVE-2018-634240Planlayın
react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an edito
KritikCVSS 9,8İstismar yokEPSS %3facebook · react-dev-utils31 Ara 2018
- CVE-2020-191440Planlayın
A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7f
KritikCVSS 9,8İstismar yokEPSS %3facebook · hermes8 Eki 2020
- CVE-2018-633140Planlayın
Buck parser-cache command loads/saves state using Java serialized object.
KritikCVSS 9,8İstismar yokEPSS %2facebook · buck31 Ara 2018
- CVE-2020-189640Planlayın
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.c
KritikCVSS 9,8İstismar yokEPSS %2facebook · hermes2 Şub 2021
- CVE-2018-633340Planlayın
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering.
KritikCVSS 9,8İstismar yokEPSS %2facebook · nuclide31 Ara 2018
- CVE-2016-687140Planlayın
Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm17 Şub 2017
- CVE-2019-1192640Planlayın
Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm6 Eyl 2019
- CVE-2016-687540Planlayın
Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm17 Şub 2017
- CVE-2016-687340Planlayın
Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm17 Şub 2017
- CVE-2016-687240Planlayın
Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm17 Şub 2017
- CVE-2016-687040Planlayın
Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm17 Şub 2017
- CVE-2019-1192540Planlayın
Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm6 Eyl 2019
- CVE-2019-1192140Planlayın
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 w
KritikCVSS 9,8İstismar yokEPSS %2facebook · proxygen25 Tem 2019
- CVE-2016-687440Planlayın
The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to r
KritikCVSS 9,8İstismar yokEPSS %2facebook · hhvm17 Şub 2017
- CVE-2020-191140Planlayın
A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes pr
KritikCVSS 9,8İstismar yokEPSS %2facebook · hermes3 Eyl 2020