Hiphop Virtual Machine

Vendor:

First CVE: Dec 28, 2014 · Active for 11 years

7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hiphop Virtual Machine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2014
11 years ago
Most Recent CVE
Jul 18, 2019
2,564 days ago

CVE Severity & Scoring

Hiphop Virtual Machine7 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (14.3%)
Unknown6 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (14.3%)
High0 (0.0%)
Unknown6 (85.7%)
User Interaction
None1 (14.3%)
Unknown6 (85.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (14.3%)
Unknown6 (85.7%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an a
Jul 18, 20199.829NONO
Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a d
Dec 28, 20147.524NONO
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attacke
Dec 28, 20147.520NONO
The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for terminatio
Dec 28, 20145.019NONO
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which make
Dec 28, 20145.019NONO
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remot
Dec 28, 20145.015NONO
Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitra
Apr 13, 20154.314NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Hiphop Virtual Machine

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.8.019.81.7%00
4.7.019.81.7%00
4.6.019.81.7%00
4.5.019.81.7%00
4.4.019.81.7%00
4.3.019.81.7%00
4.2.019.81.7%00
4.1.019.81.7%00