Facebook Thrift: vulnerabilidades y CVE
Facebook Thrift tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-45863 | Media (5.3) | 0.35% | — | 27 sept 2024 | A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from… |
| CVE-2024-45773 | Alta (7.5) | 0.48% | — | 27 sept 2024 | A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to… |
| CVE-2021-24028 | Crítica (9.8) | 1.7% | — | 14 abr 2021 | An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00. |
| CVE-2019-11939 | Alta (7.5) | 1.6% | — | 18 mar 2020 | Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory… |
| CVE-2019-3553 | Alta (7.5) | 2.1% | — | 10 mar 2020 | C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory… |
| CVE-2019-11938 | Alta (7.5) | 2.3% | — | 10 mar 2020 | Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory… |
| CVE-2019-3565 | Alta (7.5) | 2.8% | — | 6 may 2019 | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take… |
| CVE-2019-3564 | Alta (7.5) | 2.0% | — | 6 may 2019 | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to… |
| CVE-2019-3559 | Alta (7.5) | 2.0% | — | 6 may 2019 | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to… |
| CVE-2019-3558 | Alta (7.5) | 2.0% | — | 6 may 2019 | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to… |
| CVE-2019-3552 | Alta (7.5) | 2.0% | — | 6 may 2019 | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the… |