CVE-2019-11930
CRITICALHHVM <3.30.12, <4.8.5, <4.9.0-4.23.1, 4.24.0-4.28.1 - RCE
Title source: llmDescription
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Scores
CVSS v3
9.8
EPSS
0.0250
EPSS Percentile
85.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-763
Status
published
Affected Products (7)
facebook/hhvm
< 3.30.12
facebook/hhvm
facebook/hhvm
facebook/hhvm
facebook/hhvm
facebook/hhvm
facebook/hhvm
Timeline
Published
Dec 04, 2019
Tracked Since
Feb 18, 2026