CVE-2019-11932
HIGH 8.8EPSS 44.5%
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 44.53% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2019-10-03
- Updated
- 2024-08-04
Proof-of-concept exploits (26)
- 0759104103/cd-CVE-2019-119320★ · 2023-03-29
- 84KaliPleXon3/WhatsRCE1★ · 2020-06-02
- CodewithsagarG/whatsappcrash0★ · 2023-08-08
- Err0r-ICA/WhatsPayloadRCE35★ · 2022-01-02
- JasonJerry/WhatsRCE4★ · 2019-10-04
- PleXone2019/WhatsRCE0★ · 2020-01-04
- SmoZy92/CVE-2019-119326★ · 2019-12-15
- Tabni/https-github.com-awakened1712-CVE-2019-119321★ · 2021-08-17
- TinToSer/whatsapp_rce130★ · 2019-10-16
- TulungagungCyberLink/CVE-2019-119324★ · 2019-10-08
- Ysaidin78/jubilant-octo-couscous0★ · 2023-09-23
- awakened1712/CVE-2019-11932209★ · 2019-11-30
- dashtic172/abdul0★ · 2020-02-11
- dave59988/Ken0★ · 2022-03-10
- dorkerdevil/CVE-2019-11932267★ · 2021-03-19
- fastmo/CVE-2019-1193218★ · 2021-06-16
- infiniteLoopers/CVE-2019-119324★ · 2019-10-06
- jsn-OO7/whatsapp1★ · 2019-10-20
- k3vinlusec/WhatsApp-Double-Free-Vulnerability_CVE-2019-119320★ · 2021-07-23
- mRanonyMousTZ/CVE-2019-11932-whatsApp-exploit16★ · 2019-10-23
- primebeast/CVE-2019-119320★ · 2020-09-12
- solonoobs/Link-Trackers0★ · 2021-05-22
- starling021/CVE-2019-11932-SupportApp0★ · 2020-08-20
- starling021/whatsapp_rce1★ · 2020-08-20
- twinflow/truth0★ · 2022-05-04
- valbrux/CVE-2019-11932-SupportApp38★ · 2019-10-16