peter bassill · operator
$ cve CVE-2019-11929 JSON

CVE-2019-11929

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.03% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2019-10-02
Last modified2026-06-17

Affected (1)

VendorProduct
facebookhhvm

References

→ the Explorer  ·  watch your stack  ·  NVD