The HipHop Virtual Machine for PHP Project maintains a PHP execution engine with a narrow but distinct footprint, where disclosed vulnerabilities center on path-traversal and related directory-access constraints in the runtime's file-handling mechanisms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hiphop Virtual Machine For Php Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9767MEDIUM Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip. | May 22, 2016 | 4.3 | 15 | NO | NO |
CVE-2014-1439MEDIUM The libxml_disable_entity_loader function in runtime/ext/ext_simplexml.cpp in HipHop Virtual Machine for PHP (HHVM) before 2.4.0 and 2.3.x before 2.3.3 does not properly disable a | Feb 5, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hiphop Virtual Machine For Php Project.
Media articles that mention a CVE ID that affects a product developed by Hiphop Virtual Machine For Php Project — matched by CVE ID, not by vendor name.