Vulnerabilidades em Meta Platforms, Inc

13 resultados
Análise Vexday

Meta Platforms apresenta 13 vulnerabilidades catalogadas, com 6 em nível crítico, mas nenhuma sob exploração ativa conhecida no momento. A ausência de publicações recentes (últimos 90 dias) e a predominância de falhas de escrita em buffer (CWE-122) sugerem um perfil de risco estabilizado, embora a concentração em vulnerabilidades críticas demande monitoramento contínuo dos canais de atualização da empresa.

CVE-2024-50050MEDIUMLlama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potenEPSS 0.9%CVE-2021-24046A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the FaceboEPSS 0.7%CVE-2025-54949CRITICALA heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effecEPSS 0.7%CVE-2025-54951CRITICALA group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially resultEPSS 0.7%CVE-2025-54950CRITICALAn out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execEPSS 0.6%CVE-2025-54952CRITICALAn integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentEPSS 0.6%CVE-2025-30404CRITICALAn integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execuEPSS 0.6%CVE-2025-30405CRITICALAn integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, poEPSS 0.6%CVE-2025-55178MEDIUMLlama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for reEPSS 0.5%CVE-2023-30792MEDIUMAnchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where EPSS 0.4%CVE-2025-27591MEDIUMA privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/EPSS 0.4%CVE-2025-30402HIGHA heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execEPSS 0.4%CVE-2024-23347HIGHPrior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of EPSS 0.3%