Vulnerabilities (CVE)

Filtered by vendor Facebook Subscribe
Filtered by product Mcrouter
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-11923 1 Facebook 1 Mcrouter 2023-12-10 5.0 MEDIUM 7.5 HIGH
In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.
CVE-2019-11937 1 Facebook 1 Mcrouter 2023-12-10 5.0 MEDIUM 7.5 HIGH
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.