Facebook Whatsapp For Windows Phone vulnerabilities
4 known vulnerabilities affecting facebook/whatsapp_for_windows_phone.
Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-11931HIGHCVSS 7.8≥ unspecified, ≤ 2.18.3682019-11-14
CVE-2019-11931 [HIGH] CWE-121 CVE-2019-11931: A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file
A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE. This affects Android versions prior to 2.19.274, iOS versions prior to 2.19.100, Enterprise Client versions prior to 2.
cvelistv5nvd
CVE-2018-6350CRITICALCVSS 9.8v2.18.224≥ unspecified, < 2.18.2242019-06-14
CVE-2018-6350 [CRITICAL] CWE-125 CVE-2018-6350: An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. Th
An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224.
cvelistv5nvd
CVE-2019-3568CRITICALCVSS 9.8KEVv2.18.348≥ unspecified, < 2.18.3482019-05-14
CVE-2019-3568 [CRITICAL] CWE-122 CVE-2019-3568: A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially c
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, W
cvelistv5nvd
CVE-2018-6344HIGHCVSS 7.5v2.18.172≥ unspecified, < 2.18.1722018-12-31
CVE-2018-6344 [HIGH] CWE-122 CVE-2018-6344: A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is est
A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293, WhatsApp for iOS prior to v2.18.93, and WhatsApp for Windows Phone prior to v2.18.172.
cvelistv5nvd