Skip to content
Noroxi

WhatsApp records

46 published records for vendor whatsapp.

Researcher profile

Entered KEV
3 · 6.5%
Weaponized
3 · 6.5%
Pre-auth RCE
7
With a fix record
17.4%
Median publish → KEV
853 days

All records

46 records
  • A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-s

    HighCVSS 8.2KEVWeaponizedEPSS 68%

    whatsapp · whatsappJan 21, 2020

  • CVE-2019-3568
    78This week

    A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a

    CriticalCVSS 9.8KEVWeaponizedEPSS 30%

    whatsapp · whatsappMay 14, 2019

  • Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25

    MediumCVSS 5.4KEVWeaponizedEPSS 4%

    whatsapp · whatsappAug 29, 2025

  • A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in W

    HighCVSS 8.8Proof of conceptEPSS 45%

    whatsapp · whatsappOct 3, 2019

  • A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escala

    CriticalCVSS 10.0No exploitEPSS 5%

    whatsapp · whatsapp desktopSep 3, 2020

  • A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow rem

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    whatsapp · whatsappOct 23, 2019

  • An integer overflow in WhatsApp could result in remote code execution in an established video call.

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    whatsapp · whatsappSep 22, 2022

  • A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have res

    CriticalCVSS 9.8No exploitEPSS 2%

    whatsapp · whatsappNov 3, 2020

  • When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overfl

    CriticalCVSS 9.8No exploitEPSS 2%

    whatsapp · whatsappJun 14, 2019

  • When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow.

    CriticalCVSS 9.8No exploitEPSS 2%

    whatsapp · whatsappJun 14, 2019

  • A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior

    CriticalCVSS 9.8No exploitEPSS 2%

    whatsapp · whatsappOct 6, 2020

  • An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers.

    CriticalCVSS 9.8No exploitEPSS 2%

    whatsapp · whatsappJun 14, 2019

  • CVE-2018-6339
    39Monitor

    When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in.

    CriticalCVSS 9.8No exploitEPSS 2%

    whatsapp · whatsappJun 14, 2019

  • CVE-2020-1891
    39Monitor

    A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, Wh

    CriticalCVSS 9.8No exploitEPSS 1%

    whatsapp · whatsappSep 3, 2020

  • A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for

    CriticalCVSS 9.8No exploitEPSS 1%

    whatsapp · whatsappApr 6, 2021

  • A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could ha

    CriticalCVSS 9.8No exploitEPSS 1%

    whatsapp · whatsappDec 7, 2021

  • The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.

    CriticalCVSS 9.8No exploitEPSS 1%

    whatsapp · whatsappJan 4, 2022

  • CVE-2020-1894
    36Monitor

    A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior

    HighCVSS 8.8No exploitEPSS 2%

    whatsapp · whatsappSep 3, 2020

  • A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13

    CriticalCVSS 9.1No exploitEPSS 1%

    whatsapp · whatsappJun 11, 2021

  • A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp

    CriticalCVSS 9.1No exploitEPSS 1%

    whatsapp · whatsappFeb 2, 2022

  • CVE-2020-1886
    35Monitor

    A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have allowed an out-of-

    HighCVSS 8.8No exploitEPSS 1%

    whatsapp · whatsappSep 3, 2020

  • CVE-2020-1910
    33Monitor

    A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed

    HighCVSS 7.8No exploitEPSS 5%

    whatsapp · whatsappFeb 2, 2021

  • A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file

    MediumCVSS 6.7No exploitEPSS 21%

    whatsapp · whatsappApr 5, 2025

  • A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third p

    HighCVSS 7.5Proof of conceptEPSS 4%

    whatsapp · whatsappApr 6, 2021

  • CVE-2018-6344
    31Monitor

    A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established.

    HighCVSS 7.5No exploitEPSS 2%

    whatsapp · whatsappDec 31, 2018