Facebook Whatsapp Desktop vulnerabilities
5 known vulnerabilities affecting facebook/whatsapp_desktop.
Total CVEs
5
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-24042CRITICALCVSS 9.8≥ unspecified, < v2.21462022-01-04
CVE-2021-24042 [CRITICAL] CWE-122 CVE-2021-24042: The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have allowed an out-of-bounds write if a user makes a 1:1 call to a malicious
cvelistv5nvd
CVE-2020-1889CRITICALCVSS 10.0v0.3.4932≥ unspecified, < 0.3.49322020-09-03
CVE-2020-1889 [CRITICAL] CWE-265 CVE-2020-1889: A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed f
A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of privilege if combined with a remote code execution vulnerability inside the sandboxed renderer process.
cvelistv5nvd
CVE-2019-11928MEDIUMCVSS 6.1v0.3.4932≥ unspecified, < 0.3.49322020-09-03
CVE-2019-11928 [MEDIUM] CWE-79 CVE-2019-11928: An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-s
An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.
cvelistv5nvd
CVE-2019-18426HIGHCVSS 8.2KEVPoCv0.3.9309≥ unspecified, < 0.3.93092020-01-21
CVE-2019-18426 [HIGH] CWE-79 CVE-2019-18426: A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
cvelistv5nvd
CVE-2019-3571MEDIUMCVSS 5.3v0.3.3793≥ unspecified, < 0.3.37932019-07-16
CVE-2019-3571 [MEDIUM] CWE-116 CVE-2019-3571: An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows maliciou
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.
cvelistv5nvd