Facebook HHVM 4.100.0

CPE Details

Facebook HHVM 4.100.0
4.100.0
2021-03-23
17h32 +00:00
2021-03-29
10h01 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:facebook:hhvm:4.100.0:*:*:*:*:*:*:*

Informations

Vendor

facebook

Product

hhvm

Version

4.100.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-36937 2023-05-10 18h28 +00:00 HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3. Applications that call stream_socket_server or stream_socket_client functions with a URL starting with tls:// are affected.
9.8
Critique
CVE-2021-24036 2021-07-22 22h30 +00:00 Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
9.8
Critique