← back
CVE-2020-1919

CVE-2020-1919

EPSS 1.2%CWE-125
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Mar 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.
Affected products
Facebook · HHVM

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →