
CVE-2020-1909
https://notcve.org/view.php?id=CVE-2020-1909
03 Nov 2020 — A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold. Un uso de la memoria previamente liberada en una biblioteca de registro en WhatsApp para iOS anterior a versión v2.20.111 y WhatsApp Busines... • https://www.whatsapp.com/security/advisories/2020 • CWE-416: Use After Free •

CVE-2020-1907
https://notcve.org/view.php?id=CVE-2020-1907
06 Oct 2020 — A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsApp Business for iOS prior to v2.20.90, and WhatsApp for Portal prior to v173.0.0.29.505 could have allowed arbitrary code execution when parsing the contents of an RTP Extension header. Un desbordamiento de pila en WhatsApp para Android anterior a versión v2.20.196.16, WhatsApp Business para Android anterior a versión v2.20.196.12, WhatsApp para iOS a... • https://www.whatsapp.com/security/advisories/2020 • CWE-787: Out-of-bounds Write •

CVE-2020-1905
https://notcve.org/view.php?id=CVE-2020-1905
06 Oct 2020 — Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated. Los URI de Media ContentProvider usados para abrir archivos adjuntos en otras aplicaciones se generaron secuencialmente antes de WhatsApp para Android versión v2.20.185, lo que podría haber permitido que una ... • https://www.whatsapp.com/security/advisories/2020 • CWE-330: Use of Insufficiently Random Values CWE-340: Generation of Predictable Numbers or Identifiers •

CVE-2020-1906
https://notcve.org/view.php?id=CVE-2020-1906
06 Oct 2020 — A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds write when processing malformed local videos with E-AC-3 audio streams. Un desbordamiento de búfer en WhatsApp para Android anterior a versión v2.20.130 y WhatsApp Business para Android anterior a versión v2.20.46, podría haber permitido una escritura fuera de límites al procesar videos locales malformados con transmisiones de audio E-AC-3 • https://www.whatsapp.com/security/advisories/2020 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2020-1902
https://notcve.org/view.php?id=CVE-2020-1902
06 Oct 2020 — A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP. Un usuario que realiza una búsqueda rápida en un mensaje altamente reenviado en WhatsApp para Android desde versiones v2.20.108 hasta v2.20.140 o WhatsApp Business para Android desde versiones v2.20.35 hasta v2.20.49, podría haber sido enviado al servicio de Google por medio de un... • https://www.whatsapp.com/security/advisories/2020 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-319: Cleartext Transmission of Sensitive Information •