7.5
CVSSv2

CVE-2021-24025

Published: 10/03/2021 Updated: 16/03/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHVM versions before 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

facebook hhvm

facebook hhvm 4.94.0

facebook hhvm 4.95.0

facebook hhvm 4.96.0

facebook hhvm 4.97.0

facebook hhvm 4.98.0