{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T16:49:07.802","vulnerabilities":[{"cve":{"id":"CVE-2018-6349","sourceIdentifier":"cve-assign@fb.com","published":"2019-06-14T17:29:02.127","lastModified":"2026-06-17T02:01:43.220","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issue affects WhatsApp for Android prior to 2.18.248 and WhatsApp Business for Android prior to 2.18.132."},{"lang":"es","value":"Al recibir llamadas usando WhatsApp para Android, una falta de comprobación de tamaño cuando se analizan un paquete proporcionado por el remitente permite un desbordamiento basado en la pila. Este problema afecta a WhatsApp para Android anterior a versión 2.18.248 y WhatsApp Business para Android anterior a versión 2.18.132."}],"affected":[{"source":"cve-assign@fb.com","affectedData":[{"vendor":"Facebook","product":"WhatsApp for Android","versions":[{"version":"2.18.248","status":"affected"},{"version":"unspecified","lessThan":"2.18.248","versionType":"custom","status":"affected"}]},{"vendor":"Facebook","product":"WhatsApp Business for Android","versions":[{"version":"2.18.132","status":"affected"},{"version":"unspecified","lessThan":"2.18.132","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cve-assign@fb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*","versionEndExcluding":"2.18.248","matchCriteriaId":"A7390EAF-A04C-48B2-98F4-D82D9BC422C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*","versionEndExcluding":"2.18.132","matchCriteriaId":"290C4D4E-E8EA-4035-B00E-371925311ADA"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/108804","source":"cve-assign@fb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.facebook.com/security/advisories/cve-2018-6349/","source":"cve-assign@fb.com","tags":["Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/108804","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.facebook.com/security/advisories/cve-2018-6349/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}