cbcvebase.

Facebook Thrift vulnerabilities

11 known vulnerabilities affecting facebook/facebook_thrift.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2021-24028P3CRITICALCVSS 9.8≥ unspecified, < v2021.02.22.002021-04-14
CVE-2021-24028 [CRITICAL] CWE-763 CVE-2021-24028: An invalid free in Thrift's table-based serialization can cause the application to crash or potentia An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.
nvd
CVE-2024-45773P3HIGHCVSS 7.5≥ v0.0.0.0, < v2024.09.09.002024-09-27
CVE-2024-45773 [HIGH] CVE-2024-45773: A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.
nvd
CVE-2019-3565P3HIGHCVSS 7.5vv2019.05.06.00≥ unspecified, < v2019.05.06.002019-05-06
CVE-2019-3565 [HIGH] CWE-834 CVE-2019-3565: Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messag Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.05.06.
nvd
CVE-2019-3558P3HIGHCVSS 7.5vv2019.02.18.00≥ unspecified, < v2019.02.18.002019-05-06
CVE-2019-3558 [HIGH] CWE-834 CVE-2019-3558: Python Facebook Thrift servers would not error upon receiving messages with containers of fields of Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
nvd
CVE-2019-3559P3HIGHCVSS 7.5vv2019.02.18.00≥ unspecified, < v2019.02.18.002019-05-06
CVE-2019-3559 [HIGH] CWE-834 CVE-2019-3559: Java Facebook Thrift servers would not error upon receiving messages with containers of fields of un Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
nvd
CVE-2019-3564P3HIGHCVSS 7.5vv2019.03.04.00≥ unspecified, < v2019.03.04.002019-05-06
CVE-2019-3564 [HIGH] CWE-834 CVE-2019-3564: Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unkn Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
nvd
CVE-2019-3552P3HIGHCVSS 7.5vv2019.02.18.00≥ unspecified, < v2019.02.18.002019-05-06
CVE-2019-3552 [HIGH] CWE-834 CVE-2019-3552: C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
nvd
CVE-2019-11938P3HIGHCVSS 7.5≥ unspecified, < v2019.12.09.002020-03-10
CVE-2019-11938 [HIGH] CWE-770 CVE-2019-11938: Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes l Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.
nvd
CVE-2019-3553P3HIGHCVSS 7.5≥ unspecified, < v2020.02.03.002020-03-10
CVE-2019-3553 [HIGH] CWE-770 CVE-2019-3553: C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes la C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.02.03.00.
nvd
CVE-2019-11939P3HIGHCVSS 7.5≥ unspecified, < v2020.03.16.002020-03-18
CVE-2019-11939 [HIGH] CWE-770 CVE-2019-11939: Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
nvd
CVE-2024-45863P4MEDIUMCVSS 5.3≥ v2024.09.09.00, < v2024.09.23.002024-09-27
CVE-2024-45863 [MEDIUM] CVE-2024-45863: A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause t A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.
nvd