Логотип exploitDog
bind:CVE-2020-1899
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1899

Количество 4

Количество 4

ubuntu логотип

CVE-2020-1899

почти 5 лет назад

The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-1899

почти 5 лет назад

The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-1899

почти 5 лет назад

The unserialize() function supported a type code, "S", which was meant ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hqh4-hp5h-w6qj

больше 3 лет назад

The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-1899

The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-1899

The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-1899

The unserialize() function supported a type code, "S", which was meant ...

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-hqh4-hp5h-w6qj

The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу