CVE-2019-11926 is a critical vulnerability affecting Facebook HHVM versions prior to 3.30.9 and various 4.x.x versions, where insufficient boundary checks in the GD extension when processing JPEG headers can lead to out-of-bounds memory access via a crafted JPEG input. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating it can be exploited remotely with low complexity, requiring no user interaction, and potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.30.9CPE match | cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* | ||
>= 4.0.0, <= 4.8.3CPE matchmatch criteria | cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* | ||
>= 4.9.0, <= 4.15.2CPE matchmatch criteria | cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* | ||
>= 4.16.0, <= 4.16.3CPE matchmatch criteria | cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* | ||
>= 4.17.0, <= 4.17.2CPE matchmatch criteria | cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.