
CVE-2021-24043
https://notcve.org/view.php?id=CVE-2021-24043
02 Feb 2022 — A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if a user sent a malformed RTCP packet during an established call. Una comprobación de límites ausente en el código de análisis de banderas RTCP anterior a WhatsApp para Android versión v2.21.23.2, WhatsApp Business para Android versió... • https://www.whatsapp.com/security/advisories/2021 • CWE-125: Out-of-bounds Read •

CVE-2021-24041
https://notcve.org/view.php?id=CVE-2021-24041
07 Dec 2021 — A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image. Una comprobación de límites faltante en el código de desenfoque de imágenes anterior a WhatsApp para Android v2.21.22.7 y WhatsApp Business para Android v2.21.22.7 podría haber permitido una escritura fuera de límites si un usuario enviaba una imagen maliciosa • https://www.whatsapp.com/security/advisories/2021 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2021-24026
https://notcve.org/view.php?id=CVE-2021-24026
06 Apr 2021 — A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an out-of-bounds write. Una falta de comprobación de límites dentro de la tubería de decodificación de audio para llamadas de WhatsApp en WhatsApp para Android versiones anteriores a v2.21.3, WhatsApp Business para Android versiones anteriore... • https://www.whatsapp.com/security/advisories/2021 • CWE-787: Out-of-bounds Write •

CVE-2021-24027
https://notcve.org/view.php?id=CVE-2021-24027
06 Apr 2021 — A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material. Un problema de configuración de caché anterior a WhatsApp para Android versión v2.21.4.18 y WhatsApp Business para Android versión v2.21.4.18, puede haber permitido a un tercero con acceso al almacenamiento externo del dispositivo leer material TLS almacenado en caché • https://github.com/CENSUS/whatsapp-mitd-mitm • CWE-524: Use of Cache Containing Sensitive Information •

CVE-2020-1910
https://notcve.org/view.php?id=CVE-2020-1910
02 Feb 2021 — A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific image filters to a specially crafted image and sent the resulting image. Una falta de comprobación de límites en WhatsApp para Android anterior a la v2.21.1.13 y WhatsApp Business para Android anterior a la versión v2.21.1.13, podría haber permitido la lectura y escritura fuera de límites si un usuario aplicaba fil... • https://www.whatsapp.com/security/advisories/2021 • CWE-787: Out-of-bounds Write •

CVE-2020-1909
https://notcve.org/view.php?id=CVE-2020-1909
03 Nov 2020 — A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold. Un uso de la memoria previamente liberada en una biblioteca de registro en WhatsApp para iOS anterior a versión v2.20.111 y WhatsApp Busines... • https://www.whatsapp.com/security/advisories/2020 • CWE-416: Use After Free •

CVE-2020-1908
https://notcve.org/view.php?id=CVE-2020-1908
03 Nov 2020 — Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked. La autorización inapropiada de la funcionalidad Screen Lock en WhatsApp y WhatsApp Business para iOS anterior a versión v2.20.100, podría haber permitido el uso de Siri para interactuar con la aplicación WhatsApp inclusive después de que el teléfono estuviera bloqueado • https://www.whatsapp.com/security/advisories/2020 • CWE-285: Improper Authorization CWE-552: Files or Directories Accessible to External Parties •

CVE-2020-1907
https://notcve.org/view.php?id=CVE-2020-1907
06 Oct 2020 — A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsApp Business for iOS prior to v2.20.90, and WhatsApp for Portal prior to v173.0.0.29.505 could have allowed arbitrary code execution when parsing the contents of an RTP Extension header. Un desbordamiento de pila en WhatsApp para Android anterior a versión v2.20.196.16, WhatsApp Business para Android anterior a versión v2.20.196.12, WhatsApp para iOS a... • https://www.whatsapp.com/security/advisories/2020 • CWE-787: Out-of-bounds Write •

CVE-2020-1904
https://notcve.org/view.php?id=CVE-2020-1904
06 Oct 2020 — A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages. Un problema de validación de rutas en WhatsApp para iOS anterior a la v2.20.61 y en WhatsApp Business para iOS anterior a la v2.20.61 podría haber permitido atravesar directorios sobrescribiendo archivos al enviar archivos docx, xlsx y pptx especialmente ... • https://www.whatsapp.com/security/advisories/2020 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-23: Relative Path Traversal •

CVE-2020-1906
https://notcve.org/view.php?id=CVE-2020-1906
06 Oct 2020 — A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds write when processing malformed local videos with E-AC-3 audio streams. Un desbordamiento de búfer en WhatsApp para Android anterior a versión v2.20.130 y WhatsApp Business para Android anterior a versión v2.20.46, podría haber permitido una escritura fuera de límites al procesar videos locales malformados con transmisiones de audio E-AC-3 • https://www.whatsapp.com/security/advisories/2020 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •