Show filters
41 Total Results
Displaying 1-10 of 41
Sort by:
Attacker Value
Unknown
CVE-2019-3568
Disclosure Date: May 14, 2019 (last updated July 03, 2024)
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
1
Attacker Value
Unknown
CVE-2023-38538
Disclosure Date: October 04, 2023 (last updated October 11, 2023)
A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.
0
Attacker Value
Unknown
CVE-2023-38537
Disclosure Date: October 04, 2023 (last updated October 11, 2023)
A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.
0
Attacker Value
Unknown
CVE-2022-27492
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.
0
Attacker Value
Unknown
CVE-2022-36934
Disclosure Date: September 22, 2022 (last updated October 08, 2023)
An integer overflow in WhatsApp could result in remote code execution in an established video call.
0
Attacker Value
Unknown
CVE-2020-20096
Disclosure Date: March 23, 2022 (last updated October 07, 2023)
Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
0
Attacker Value
Unknown
CVE-2021-24043
Disclosure Date: February 02, 2022 (last updated October 07, 2023)
A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if a user sent a malformed RTCP packet during an established call.
0
Attacker Value
Unknown
CVE-2021-24042
Disclosure Date: January 04, 2022 (last updated October 07, 2023)
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have allowed an out-of-bounds write if a user makes a 1:1 call to a malicious actor.
0
Attacker Value
Unknown
CVE-2021-24041
Disclosure Date: December 07, 2021 (last updated October 07, 2023)
A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image.
0
Attacker Value
Unknown
CVE-2021-24035
Disclosure Date: June 11, 2021 (last updated November 28, 2024)
A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files.
0