CVE-2019-11929

CRITICAL

HHVM <3.30.10, <4.8.5, <4.18.2, <4.19.0-4.20.2 - RCE

Title source: llm
STIX 2.1

Description

Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0473
EPSS Percentile 89.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (9)
facebook/hhvm 4.19.0
facebook/hhvm 4.19.1
facebook/hhvm 4.20.0
facebook/hhvm 4.20.1
facebook/hhvm 4.20.2
facebook/hhvm 4.21.0
facebook/hhvm 4.22.0
facebook/hhvm 4.23.0
facebook/hhvm < 3.30.10
Published Oct 02, 2019
Tracked Since Feb 18, 2026