
CVE-2020-1902
https://notcve.org/view.php?id=CVE-2020-1902
06 Oct 2020 — A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP. Un usuario que realiza una búsqueda rápida en un mensaje altamente reenviado en WhatsApp para Android desde versiones v2.20.108 hasta v2.20.140 o WhatsApp Business para Android desde versiones v2.20.35 hasta v2.20.49, podría haber sido enviado al servicio de Google por medio de un... • https://www.whatsapp.com/security/advisories/2020 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-319: Cleartext Transmission of Sensitive Information •

CVE-2020-1903
https://notcve.org/view.php?id=CVE-2020-1903
06 Oct 2020 — An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts. Un problema al descomprimir documentos docx, pptx y xlsx en WhatsApp para iOS anterior a versión v2.20.61 y WhatsApp Business para iOS anterior a versión v2.20.... • https://www.whatsapp.com/security/advisories/2020 • CWE-400: Uncontrolled Resource Consumption •

CVE-2020-1891
https://notcve.org/view.php?id=CVE-2020-1891
03 Sep 2020 — A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, WhatsApp for iPhone prior to v2.20.20, and WhatsApp Business for iPhone prior to v2.20.20 could have allowed an out-of-bounds write on 32-bit devices. Un parámetro controlado por usuario usado en videollamada en WhatsApp para Android versiones anteriores a v2.20.17, WhatsApp Business para Android versiones anteriores a v2.20.7, WhatsApp para iPhone versiones anteriores a ... • https://www.whatsapp.com/security/advisories/2020 • CWE-787: Out-of-bounds Write •

CVE-2020-1894
https://notcve.org/view.php?id=CVE-2020-1894
03 Sep 2020 — A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.20.30 could have allowed arbitrary code execution when playing a specially crafted push to talk message. Un desbordamiento de escritura de pila en WhatsApp para Android versiones anteriores a v2.20.35, WhatsApp Business para Android versiones anteriores a v2.20.20, WhatsApp para iPhone versiones anteriores a v2.... • https://www.whatsapp.com/security/advisories/2020 • CWE-787: Out-of-bounds Write •

CVE-2020-1886
https://notcve.org/view.php?id=CVE-2020-1886
03 Sep 2020 — A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have allowed an out-of-bounds write via a specially crafted video stream after receiving and answering a malicious video call. Un desbordamiento del búfer en WhatsApp para Android versiones anteriores a v2.20.11 y WhatsApp Business para Android versiones anteriores a v2.20.2, podría haber permitido una escritura fuera de límites por medio de una transmisión de video especialmente diseñada des... • https://www.whatsapp.com/security/advisories/2020 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •

CVE-2020-1890
https://notcve.org/view.php?id=CVE-2020-1890
03 Sep 2020 — A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have caused the recipient of a sticker message containing deliberately malformed data to load an image from a sender-controlled URL without user interaction. Un problema de comprobación de URL en WhatsApp para Android versiones anteriores a v2.20.11 y WhatsApp Business para Android versiones anteriores a v2.20.2, podría haber causado que el destinatario de un mensaje sticker que contenía... • https://www.whatsapp.com/security/advisories/2020 • CWE-20: Improper Input Validation •

CVE-2019-11931
https://notcve.org/view.php?id=CVE-2019-11931
14 Nov 2019 — A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE. This affects Android versions prior to 2.19.274, iOS versions prior to 2.19.100, Enterprise Client versions prior to 2.25.3, Business for Android versions prior to 2.19.104 and Business for iOS versions prior to 2.19.100. Se podría desencadenar un desbordamiento de búfer en la ... • https://github.com/nop-team/CVE-2019-11931 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2019-3566
https://notcve.org/view.php?id=CVE-2019-3566
10 May 2019 — A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103, as well as WhatsApp Business for Android starting in v2.19.22 until v2.19.38. Se descubrió un error en la lógica de mensajería de WhatsApp para ... • https://www.facebook.com/security/advisories/cve-2019-3566 • CWE-284: Improper Access Control •