Hermes
Vendor:
First CVE: Sep 4, 2020 · Active for 5 years
20
Total CVEs
More Total CVEs than 94% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
9.2
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hermes over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2020
5 years ago
Most Recent CVE
May 18, 2023
1,163 days ago
CVE Severity & Scoring
Hermes20 CVEs
30%
70%
All CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High2 (10.0%)
Unknown0 (0.0%)
User Interaction
None20 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None20 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30470CRITICAL A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could ha | May 18, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-23556CRITICAL An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code du | May 18, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-24044CRITICAL By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out | Jan 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40138CRITICAL An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and su | Oct 11, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-32234CRITICAL An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potentially execute arbitrary code via c | Oct 11, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-1911CRITICAL A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prior to commit fe52854cdf6725c2eaa9e12599 | Sep 4, 2020 | 9.8 | 30 | NO | NO |
CVE-2023-28081CRITICAL A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a ca | May 18, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-25933CRITICAL A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted Jav | May 18, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-24045CRITICAL A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the applicat | Dec 13, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-24037CRITICAL A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code v | Jun 15, 2021 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Hermes
Top CWEs
Versions
No cataloged versions.