{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T16:48:58.079","vulnerabilities":[{"cve":{"id":"CVE-2018-6339","sourceIdentifier":"cve-assign@fb.com","published":"2019-06-14T17:29:02.003","lastModified":"2026-06-17T02:01:41.700","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in. An off-by-one error meant that data was written beyond the allocated space on the stack. This issue affects WhatsApp for Android starting in version 2.18.180 and was fixed in version 2.18.295. It also affects WhatsApp Business for Android starting in version v2.18.103 and was fixed in version v2.18.150."},{"lang":"es","value":"Cuando se reciben llamadas con WhatsApp en Android, en la asignación de pila no se considera adecuadamente la cantidad de datos que están pasando. Un error de uno en uno significaba que los datos se escribían fuera del espacio asignado en la pila. Este problema afecta a WhatsApp para Android a partir de la versión 2.18.180 y se corrigió en la versión 2.18.295. También afecta a WhatsApp Business para Android a partir de la versión v2.18.103 y se corrigió en la versión v2.18.150."}],"affected":[{"source":"cve-assign@fb.com","affectedData":[{"vendor":"Facebook","product":"WhatsApp for Android","versions":[{"version":"2.18.295","status":"affected"},{"version":"2.18.180","lessThan":"unspecified","versionType":"custom","status":"affected"},{"version":"unspecified","lessThan":"2.18.180","versionType":"custom","status":"unaffected"}]},{"vendor":"Facebook","product":"WhatsApp Business for Android","versions":[{"version":"2.18.150","status":"affected"},{"version":"2.18.103","lessThan":"unspecified","versionType":"custom","status":"affected"},{"version":"unspecified","lessThan":"2.18.103","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cve-assign@fb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-119"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*","versionStartIncluding":"2.18.180","versionEndExcluding":"2.18.295","matchCriteriaId":"6AF2CF4A-DE98-48CC-A13A-E168EA4678E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*","versionStartIncluding":"2.18.103","versionEndExcluding":"2.18.150","matchCriteriaId":"9FF4FF16-10F8-46BB-8A68-6044A193E5E3"}]}]}],"references":[{"url":"https://www.facebook.com/security/advisories/cve-2018-6339/","source":"cve-assign@fb.com","tags":["Third Party Advisory"]},{"url":"https://www.facebook.com/security/advisories/cve-2018-6339/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}