CVE-2020-1892

HIGH

HHVM <4.45.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to information leak and DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions between 4.33.0 and 4.38.0 (inclusive), versions between 4.9.0 and 4.32.0 (inclusive), and versions prior to 4.8.7.

Scores

CVSS v3 8.1
EPSS 0.0061
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (8)
facebook/hhvm 4.39.0
facebook/hhvm 4.40.0
facebook/hhvm 4.41.0
facebook/hhvm 4.42.0
facebook/hhvm 4.43.0
facebook/hhvm 4.44.0
facebook/hhvm 4.45.0
facebook/hhvm < 4.8.7
Published Mar 03, 2020
Tracked Since Feb 18, 2026