Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.14.5"
}
],
"cpe": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6872.json"
"2026-07-08T12:44:00Z"
[
{
"target": {
"file": "hphp/runtime/base/string-util.cpp"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2016-6872-ff462bff",
"signature_version": "v1",
"source": "https://github.com/facebook/hhvm/commit/2c9a8fcc73a151608634d3e712973d192027c271",
"digest": {
"line_hashes": [
"238431082941683571881043329064853029846",
"90012039958666104044987661821392023337",
"99491763227833211429850463633399313271",
"114462067825914996416718107681050641214",
"333721075058452031515053542804959195010"
],
"threshold": 0.9
}
}
]