Exposición de HHVM

Web servers
12
score de exposición
41
sitios usan
0
en explotación
2
críticos
Análisis Vexday

Com 31 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o HHVM apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere pressão ofensiva relativamente baixa no momento. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tipicamente expõe superfícies para vazamento de memória ou potencial execução de código. A CVE mais relevante no contexto atual é CVE-2019-11929, com score EPSS de aproximadamente 0,04, indicando probabilidade de exploração ainda contida, mas não desprezível para ambientes que mantêm versões desatualizadas. A ausência de novas CVEs nos últimos 90 dias pode refletir menor atividade de pesquisa sobre a tecnologia, o que não equivale necessariamente a ausência de risco residual nas duas vulnerabilidades de severidade crítica catalogadas.

CVEs

31 resultados
CVE-2020-1917xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not usingEPSS 1.4%CVE-2020-1899The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arEPSS 1.2%CVE-2020-1918In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory priEPSS 1.2%CVE-2020-1919Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer thanEPSS 1.2%CVE-2020-1898The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could causeEPSS 1.2%CVE-2020-1921In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within tEPSS 1.2%CVE-2020-1893Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This issue affects HHVM EPSS 1.1%CVE-2020-1888Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affectEPSS 1.1%CVE-2020-1892Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to informatioEPSS 1.1%CVE-2018-6332MEDIUMA potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate EPSS 1.1%CVE-2022-36937CRITICALHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerouEPSS 0.5%