CVE-2019-11930
Estado: ModificadaCrítica (9.8)—
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.25%
- Percentil entre todas las CVEs puntuadas: 88
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-763
- CWE-763
Referencias
- https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36
- https://hhvm.com/blog/2019/10/28/security-update.html
- https://www.facebook.com/security/advisories/cve-2019-11930
- https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36
- https://hhvm.com/blog/2019/10/28/security-update.html
- https://www.facebook.com/security/advisories/cve-2019-11930
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-11930",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-assign@fb.com",
"affectedData": [
{
"vendor": "Facebook",
"product": "HHVM",
"versions": [
{
"status": "affected",
"version": "4.28.2"
},
{
"status": "affected",
"version": "4.28.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.27.1"
},
{
"status": "affected",
"version": "4.27.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.26.1"
},
{
"status": "affected",
"version": "4.26.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.25.1"
},
{
"status": "affected",
"version": "4.25.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.24.1"
},
{
"status": "affected",
"version": "4.24.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.23.2"
},
{
"status": "affected",
"version": "4.9.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.8.6"
},
{
"status": "affected",
"version": "4.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.30.12"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "3.30.12",
"versionType": "custom"
}
]
}
]
}
],
"published": "2019-12-04T17:16:43.087",
"references": [
{
"url": "https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36",
"tags": [
"Patch"
],
"source": "cve-assign@fb.com"
},
{
"url": "https://hhvm.com/blog/2019/10/28/security-update.html",
"tags": [
"Vendor Advisory"
],
"source": "cve-assign@fb.com"
},
{
"url": "https://www.facebook.com/security/advisories/cve-2019-11930",
"tags": [
"Vendor Advisory"
],
"source": "cve-assign@fb.com"
},
{
"url": "https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hhvm.com/blog/2019/10/28/security-update.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.facebook.com/security/advisories/cve-2019-11930",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve-assign@fb.com",
"description": [
{
"lang": "en",
"value": "CWE-763"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-763"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1."
},
{
"lang": "es",
"value": "Una liberación inválida en mb_detect_order puede causar que la aplicación se bloquee o potencialmente resulte en una ejecución de código remota. Este problema afecta HHVM versiones anteriores a la versión 3.30.12, todas las versiones entre 4.0.0 y 4.8.5, todas las versiones entre 4.9.0 y 4.23.1, así como las versiones 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0 y 4.28.1."
}
],
"lastModified": "2026-06-17T02:13:51.403",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8452024-B97D-4B7B-BB28-AC04328E67B2",
"versionEndExcluding": "3.30.12"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47FAA7FF-64A7-451F-A389-6CA4240D7871",
"versionEndIncluding": "4.8.5",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12366B66-DE3D-4387-83BC-E01C77393D58",
"versionEndIncluding": "4.23.1",
"versionStartIncluding": "4.9.0"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:4.24.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76F33DEA-0DB2-46B5-82C3-CA75D07C952D"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:4.25.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B098BF0-EA28-44FA-A5D0-BDE05C2E9FE8"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:4.26.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0950ED00-A5DC-4DA6-906F-CDC03EE2DA5A"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:4.27.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D77D46F2-A17B-4CEA-A003-F7952EE3342D"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:4.28.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D53212BA-6BF8-4FE2-980C-371D5EF170E5"
},
{
"criteria": "cpe:2.3:a:facebook:hhvm:4.28.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F182E9B3-838C-4AFA-94B5-77D30098712E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-assign@fb.com"
}