Page 2 of 44 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

07 Dec 2021 — A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image. Una comprobación de límites faltante en el código de desenfoque de imágenes anterior a WhatsApp para Android v2.21.22.7 y WhatsApp Business para Android v2.21.22.7 podría haber permitido una escritura fuera de límites si un usuario enviaba una imagen maliciosa • https://www.whatsapp.com/security/advisories/2021 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVSS: 9.1EPSS: 0%CPEs: 2EXPL: 0

11 Jun 2021 — A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files. Una falta de comprobación de los nombres de archivo al descomprimir archivos anterior a versión de WhatsApp para Android versión v2.21.8.13 y WhatsApp Business para Android versión v2.21.8.13, podría haber permitido ataques de salto de rutas que sobrescribieran los archivos de WhatsApp • https://www.whatsapp.com/security/advisories/2021 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 0

06 Apr 2021 — A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an out-of-bounds write. Una falta de comprobación de límites dentro de la tubería de decodificación de audio para llamadas de WhatsApp en WhatsApp para Android versiones anteriores a v2.21.3, WhatsApp Business para Android versiones anteriore... • https://www.whatsapp.com/security/advisories/2021 • CWE-787: Out-of-bounds Write •

CVSS: 7.5EPSS: 14%CPEs: 2EXPL: 1

06 Apr 2021 — A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material. Un problema de configuración de caché anterior a WhatsApp para Android versión v2.21.4.18 y WhatsApp Business para Android versión v2.21.4.18, puede haber permitido a un tercero con acceso al almacenamiento externo del dispositivo leer material TLS almacenado en caché • https://github.com/CENSUS/whatsapp-mitd-mitm • CWE-524: Use of Cache Containing Sensitive Information •

CVSS: 7.8EPSS: 2%CPEs: 2EXPL: 0

02 Feb 2021 — A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific image filters to a specially crafted image and sent the resulting image. Una falta de comprobación de límites en WhatsApp para Android anterior a la v2.21.1.13 y WhatsApp Business para Android anterior a la versión v2.21.1.13, podría haber permitido la lectura y escritura fuera de límites si un usuario aplicaba fil... • https://www.whatsapp.com/security/advisories/2021 • CWE-787: Out-of-bounds Write •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

03 Nov 2020 — A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold. Un uso de la memoria previamente liberada en una biblioteca de registro en WhatsApp para iOS anterior a versión v2.20.111 y WhatsApp Busines... • https://www.whatsapp.com/security/advisories/2020 • CWE-416: Use After Free •

CVSS: 4.6EPSS: 0%CPEs: 2EXPL: 0

03 Nov 2020 — Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked. La autorización inapropiada de la funcionalidad Screen Lock en WhatsApp y WhatsApp Business para iOS anterior a versión v2.20.100, podría haber permitido el uso de Siri para interactuar con la aplicación WhatsApp inclusive después de que el teléfono estuviera bloqueado • https://www.whatsapp.com/security/advisories/2020 • CWE-285: Improper Authorization CWE-552: Files or Directories Accessible to External Parties •

CVSS: 9.8EPSS: 1%CPEs: 5EXPL: 0

06 Oct 2020 — A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsApp Business for iOS prior to v2.20.90, and WhatsApp for Portal prior to v173.0.0.29.505 could have allowed arbitrary code execution when parsing the contents of an RTP Extension header. Un desbordamiento de pila en WhatsApp para Android anterior a versión v2.20.196.16, WhatsApp Business para Android anterior a versión v2.20.196.12, WhatsApp para iOS a... • https://www.whatsapp.com/security/advisories/2020 • CWE-787: Out-of-bounds Write •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

06 Oct 2020 — A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages. Un problema de validación de rutas en WhatsApp para iOS anterior a la v2.20.61 y en WhatsApp Business para iOS anterior a la v2.20.61 podría haber permitido atravesar directorios sobrescribiendo archivos al enviar archivos docx, xlsx y pptx especialmente ... • https://www.whatsapp.com/security/advisories/2020 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

06 Oct 2020 — Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated. Los URI de Media ContentProvider usados para abrir archivos adjuntos en otras aplicaciones se generaron secuencialmente antes de WhatsApp para Android versión v2.20.185, lo que podría haber permitido que una ... • https://www.whatsapp.com/security/advisories/2020 • CWE-330: Use of Insufficiently Random Values CWE-340: Generation of Predictable Numbers or Identifiers •