VYPR

Vendor CVEs

Facebook

All CVEs

183 total · sorted by risk
  • CVE-2019-11927HigSep 27, 2019
    risk 0.51cvss 7.8epss 0.01

    An integer overflow in WhatsApp media parsing libraries allows a remote attacker to perform an out-of-bounds write on the heap via specially-crafted EXIF tags in WEBP images. This issue affects WhatsApp for Android before version 2.19.143 and WhatsApp for iOS before version…

  • CVE-2024-45773HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.00

    A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.

  • CVE-2022-27810HigOct 6, 2022
    risk 0.49cvss 7.5epss 0.01

    It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.

  • CVE-2021-24027HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.04

    A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material.

  • CVE-2020-1902HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.01

    A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.

  • CVE-2020-1890HigSep 3, 2020
    risk 0.49cvss 7.5epss 0.01

    A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have caused the recipient of a sticker message containing deliberately malformed data to load an image from a sender-controlled URL without user interaction.

  • CVE-2018-6344HigDec 31, 2018
    risk 0.49cvss 7.5epss 0.02

    A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293, WhatsApp for iOS prior to v2.18.93, and WhatsApp for…

  • CVE-2015-7265HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.01

    Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.

  • CVE-2015-7263HigApr 10, 2017
    risk 0.49cvss 7.5epss 0.01

    The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.

  • CVE-2021-39207HigSep 10, 2021
    risk 0.48cvss 8.4epss 0.02

    parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary code execution. This security bug is…

  • CVE-2025-55184HigDec 11, 2025
    risk 0.47cvss 7.5epss 0.67

    A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The…

  • CVE-2025-55177MedKEVAug 29, 2025
    risk 0.47cvss 5.4epss 0.04

    Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a…

  • CVE-2025-30403HigJul 11, 2025
    risk 0.46cvss 8.1epss 0.00

    A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

  • CVE-2020-1913HigSep 9, 2020
    risk 0.46cvss 8.1epss 0.01

    An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the…

  • CVE-2020-1912HigSep 9, 2020
    risk 0.46cvss 8.1epss 0.02

    An out-of-bounds read/write vulnerability when executing lazily compiled inner generator functions in Facebook Hermes prior to commit 091835377369c8fd5917d9b87acffa721ad2a168 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only…

  • CVE-2025-30401MedApr 5, 2025
    risk 0.45cvss 6.7epss 0.22

    A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to…

  • CVE-2025-67779HigDec 12, 2025
    risk 0.43cvss 7.5epss 0.20

    It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads…

  • CVE-2026-23870HigMay 6, 2026
    risk 0.42cvss 7.5epss 0.02

    A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack,…

  • CVE-2026-23863MedMay 1, 2026
    risk 0.42cvss 6.5epss 0.01

    An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not…

  • CVE-2026-23864HigJan 26, 2026
    risk 0.42cvss 7.5epss 0.02

    Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server…

  • CVE-2022-4899HigMar 31, 2023
    risk 0.42cvss 7.5epss 0.02

    A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

  • CVE-2020-20094MedMar 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages

  • CVE-2020-20093MedMar 23, 2022
    risk 0.42cvss 6.5epss 0.02

    The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

  • CVE-2020-1920HigJun 1, 2021
    risk 0.42cvss 7.5epss 0.01

    A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.

  • CVE-2020-1915HigOct 26, 2020
    risk 0.42cvss 7.5epss 0.02

    An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable…

  • CVE-2019-11939HigMar 18, 2020
    risk 0.42cvss 7.5epss 0.02

    Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This…

  • CVE-2019-3564HigMay 6, 2019
    risk 0.42cvss 7.5epss 0.02

    Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue…

  • CVE-2023-30792MedApr 29, 2023
    risk 0.40cvss 6.1epss 0.00

    Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.

  • CVE-2019-11928MedSep 3, 2020
    risk 0.40cvss 6.1epss 0.01

    An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.

  • CVE-2019-3562MedApr 29, 2019
    risk 0.40cvss 6.1epss 0.01

    A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.

  • CVE-2025-55183MedDec 11, 2025
    risk 0.39cvss 5.3epss 0.64

    An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack.…

  • CVE-2019-3566MedMay 10, 2019
    risk 0.38cvss 5.9epss 0.01

    A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not…

  • CVE-2018-6332MedDec 3, 2018
    risk 0.38cvss 5.9epss 0.01

    A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources. This affects all supported versions of HHVM (3.24.3 and 3.21.7 and below) when using the proxygen server to handle HTTP2…

  • CVE-2025-27591MedMar 11, 2025
    risk 0.37cvss 6.8epss 0.00

    A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files…

  • CVE-2023-38537MedOct 4, 2023
    risk 0.36cvss 5.6epss 0.00

    A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.

  • CVE-2021-24031MedMar 4, 2021
    risk 0.36cvss 5.5epss 0.00

    In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

  • CVE-2020-1904MedOct 6, 2020
    risk 0.36cvss 5.5epss 0.01

    A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.

  • CVE-2020-1903MedOct 6, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment…

  • CVE-2025-55179MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We…

  • CVE-2023-5654MedOct 19, 2023
    risk 0.35cvss 6.5epss 0.00

    The React Developer Tools extension registers a message listener with window.addEventListener('message', ) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received…

  • CVE-2020-1901MedOct 6, 2020
    risk 0.35cvss 5.3epss 0.01

    Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message.

  • CVE-2019-3571MedJul 16, 2019
    risk 0.35cvss 5.3epss 0.01

    An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.

  • CVE-2024-45863MedSep 27, 2024
    risk 0.34cvss 5.3epss 0.00

    A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects Facebook Thrift from v2024.09.09.00 until v2024.09.23.00.

  • CVE-2023-38538MedOct 4, 2023
    risk 0.33cvss 5.0epss 0.00

    A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.

  • CVE-2018-6341MedDec 31, 2018
    risk 0.33cvss 6.1epss 0.03

    React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and…

  • CVE-2021-24032MedMar 4, 2021
    risk 0.31cvss 4.7epss 0.00

    Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or…

  • CVE-2021-24033MedMar 9, 2021
    risk 0.30cvss 5.6epss 0.03

    react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be executed. This function is typically used from react-scripts (in Create React App projects), where the usage is safe. Only when this…

  • CVE-2020-1908MedNov 3, 2020
    risk 0.30cvss 4.6epss 0.00

    Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.

  • CVE-2016-1000109MedFeb 19, 2020
    risk 0.28cvss 5.3epss 0.05

    HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's…

  • CVE-2020-1905LowOct 6, 2020
    risk 0.22cvss 3.3epss 0.01

    Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the…