Filtered by vendor Facebook Subscriptions
Filtered by product Mcrouter Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-11923 1 Facebook 1 Mcrouter 2020-08-24 7.5 High
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.
CVE-2019-11937 1 Facebook 1 Mcrouter 2020-08-24 7.5 High
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.