Facebook Thrift vulnerabilities
11 known vulnerabilities affecting facebook/facebook_thrift.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-24028P3CRITICALCVSS 9.8≥ unspecified, < v2021.02.22.002021-04-14
CVE-2021-24028 [CRITICAL] CWE-763 CVE-2021-24028: An invalid free in Thrift's table-based serialization can cause the application to crash or potentia
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.
nvd
CVE-2024-45773P3HIGHCVSS 7.5≥ v0.0.0.0, < v2024.09.09.002024-09-27
CVE-2024-45773 [HIGH] CVE-2024-45773: A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash
A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.
nvd
CVE-2019-3565P3HIGHCVSS 7.5vv2019.05.06.00≥ unspecified, < v2019.05.06.002019-05-06
CVE-2019-3565 [HIGH] CWE-834 CVE-2019-3565: Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messag
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.05.06.
nvd
CVE-2019-3558P3HIGHCVSS 7.5vv2019.02.18.00≥ unspecified, < v2019.02.18.002019-05-06
CVE-2019-3558 [HIGH] CWE-834 CVE-2019-3558: Python Facebook Thrift servers would not error upon receiving messages with containers of fields of
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
nvd
CVE-2019-3559P3HIGHCVSS 7.5vv2019.02.18.00≥ unspecified, < v2019.02.18.002019-05-06
CVE-2019-3559 [HIGH] CWE-834 CVE-2019-3559: Java Facebook Thrift servers would not error upon receiving messages with containers of fields of un
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
nvd
CVE-2019-3564P3HIGHCVSS 7.5vv2019.03.04.00≥ unspecified, < v2019.03.04.002019-05-06
CVE-2019-3564 [HIGH] CWE-834 CVE-2019-3564: Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unkn
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
nvd
CVE-2019-3552P3HIGHCVSS 7.5vv2019.02.18.00≥ unspecified, < v2019.02.18.002019-05-06
CVE-2019-3552 [HIGH] CWE-834 CVE-2019-3552: C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
nvd
CVE-2019-11938P3HIGHCVSS 7.5≥ unspecified, < v2019.12.09.002020-03-10
CVE-2019-11938 [HIGH] CWE-770 CVE-2019-11938: Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes l
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.
nvd
CVE-2019-3553P3HIGHCVSS 7.5≥ unspecified, < v2020.02.03.002020-03-10
CVE-2019-3553 [HIGH] CWE-770 CVE-2019-3553: C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes la
C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.02.03.00.
nvd
CVE-2019-11939P3HIGHCVSS 7.5≥ unspecified, < v2020.03.16.002020-03-18
CVE-2019-11939 [HIGH] CWE-770 CVE-2019-11939: Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
nvd
CVE-2024-45863P4MEDIUMCVSS 5.3≥ v2024.09.09.00, < v2024.09.23.002024-09-27
CVE-2024-45863 [MEDIUM] CVE-2024-45863: A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause t
A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.
nvd