Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Facebook Hermes 缓冲区错误漏洞
Vulnerability Description
Facebook Hermes是美国Facebook公司的一个JavaScript引擎。该引擎针对React Native应用,去提高移动客户端应用App的性能,但是对浏览器 & Node.js 等服务端基础架构并不适用。 Facebook Hermes a6dcafe6ded8e61658b40f5699878cd19a481f80 之前版本存在安全漏洞,该漏洞源于将 BigInt 转换为 Number 错误,攻击者利用该漏洞可以执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A