{"id":"CVE-2016-1000006","details":"hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.","modified":"2026-07-08T12:35:40.687830Z","published":"2019-11-19T15:15:11.007Z","references":[{"type":"WEB","url":"https://www.mail-archive.com/debian-devel-changes%40lists.debian.org/msg506329.html"},{"type":"ADVISORY","url":"https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-1000006.html"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2016-1000006"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/hhvm","events":[{"introduced":"0"},{"fixed":"a64ddf139c5e2e65659028077735ee9cc2971835"}],"database_specific":{"cpe":"cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.12.11"}],"source":"CPE_RANGE"}}],"versions":["HHVM-3.12.10","HHVM-3.12.9","HHVM-3.12.8","HHVM-3.12.7","HHVM-3.12.6","HHVM-3.12.5","HHVM-3.12.4","HHVM-3.12.3","HHVM-3.12.2","HHVM-3.12.1","HHVM-3.12.0","gcc-4.6","HPHP-2.1.0","src-hphp","pre-hhvm"],"database_specific":{"vanir_signatures_modified":"2026-07-08T12:35:40Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["94780875309429617507039189253768797907","299598516194893646037602763402043654662","149905275439727761391743046235245728815","337200168275528921883647987451330904820"],"threshold":0.9},"id":"CVE-2016-1000006-8eef412d","signature_type":"Line","signature_version":"v1","source":"https://github.com/facebook/hhvm/commit/a64ddf139c5e2e65659028077735ee9cc2971835","target":{"file":"hphp/runtime/version.h"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1000006.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}