Thrift
Vendor:
First CVE: May 6, 2019 · Active for 7 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Thrift over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2019
7 years ago
Most Recent CVE
Apr 14, 2021
1,927 days ago
CVE Severity & Scoring
Thrift9 CVEs
89%
11%
All CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24028CRITICAL An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Fa | Apr 14, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-11939HIGH Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messag | Mar 18, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-11938HIGH Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages | Mar 10, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-3558HIGH Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which wou | May 6, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-3552HIGH C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages | May 6, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-3564HIGH Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would t | May 6, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-3559HIGH Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would | May 6, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-3553HIGH C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages | Mar 10, 2020 | 7.5 | 22 | NO | NO |
CVE-2019-3565HIGH Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients cou | May 6, 2019 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Thrift
Top CWEs
Versions
No cataloged versions.