Vulnerabilities > Whatsapp > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-11933 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code or cause a denial of service.
network
low complexity
libpl-droidsonroids-gif-project whatsapp CWE-787
critical
9.8
2019-06-14 CVE-2018-6350 Out-of-bounds Read vulnerability in Whatsapp
An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers.
network
low complexity
whatsapp CWE-125
critical
9.8
2019-06-14 CVE-2018-6349 Out-of-bounds Write vulnerability in Whatsapp
When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow.
network
low complexity
whatsapp CWE-787
critical
9.8
2019-06-14 CVE-2018-6339 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Whatsapp
When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in.
network
low complexity
whatsapp CWE-119
critical
9.8
2019-06-14 CVE-2018-20655 Out-of-bounds Write vulnerability in Whatsapp
When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow.
network
low complexity
whatsapp CWE-787
critical
9.8
2019-05-14 CVE-2019-3568 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Whatsapp
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.
network
low complexity
whatsapp CWE-119
critical
9.8