Magic UI
by Huawei
CVEs (253)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31756 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-31755 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-31751 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2021-37103 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2022 | There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-40045 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-40037 | Med | 0.36 | 5.5 | 0.00 | Jan 10, 2022 | There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart. | ||
| CVE-2020-9149 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2021 | An application error verification vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to modify and delete user SMS messages. | ||
| CVE-2020-9148 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2021 | An application bypass mechanism vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to delete user SMS messages. | ||
| CVE-2020-9146 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2021 | A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to cause memory leakage and doS attacks by carefully constructing attack scenarios. | ||
| CVE-2021-40009 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2022 | There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2021-37032 | Med | 0.35 | 5.3 | 0.01 | Nov 23, 2021 | There is a Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Digital Balance to fail to work. | ||
| CVE-2021-37029 | Med | 0.35 | 5.3 | 0.01 | Nov 23, 2021 | There is an Identity verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2021-36997 | Med | 0.35 | 5.3 | 0.01 | Oct 28, 2021 | There is a Low memory error in Huawei Smartphone due to the unlimited size of images to be parsed.Successful exploitation of this vulnerability may cause the Gallery or Files app to exit unexpectedly. | ||
| CVE-2021-22404 | Med | 0.35 | 5.3 | 0.01 | Oct 28, 2021 | There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-22344 | Med | 0.35 | 5.3 | 0.01 | Jul 1, 2021 | There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS. | ||
| CVE-2021-22347 | Med | 0.35 | 5.3 | 0.01 | Jul 1, 2021 | There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS. | ||
| CVE-2020-9143 | Med | 0.35 | 5.3 | 0.01 | Jan 13, 2021 | There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability may lead to low-sensitive information exposure. | ||
| CVE-2020-9138 | Med | 0.35 | 5.3 | 0.01 | Jan 13, 2021 | There is a heap-based buffer overflow vulnerability in some Huawei Smartphone, Successful exploit of this vulnerability can cause process exceptions during updating. | ||
| CVE-2021-46811 | Med | 0.34 | 5.3 | 0.00 | Jun 13, 2022 | HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information. | ||
| CVE-2021-37114 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | There is an Out-of-bounds read vulnerability in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. |
- risk 0.36cvss 5.5epss 0.00
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.36cvss 5.5epss 0.00
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
- risk 0.36cvss 5.5epss 0.00
The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.
- risk 0.36cvss 5.5epss 0.00
There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.
- risk 0.36cvss 5.5epss 0.00
An application error verification vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to modify and delete user SMS messages.
- risk 0.36cvss 5.5epss 0.00
An application bypass mechanism vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to delete user SMS messages.
- risk 0.36cvss 5.5epss 0.00
A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers can exploit this vulnerability to cause memory leakage and doS attacks by carefully constructing attack scenarios.
- risk 0.35cvss 5.3epss 0.01
There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
- risk 0.35cvss 5.3epss 0.01
There is a Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Digital Balance to fail to work.
- risk 0.35cvss 5.3epss 0.01
There is an Identity verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- risk 0.35cvss 5.3epss 0.01
There is a Low memory error in Huawei Smartphone due to the unlimited size of images to be parsed.Successful exploitation of this vulnerability may cause the Gallery or Files app to exit unexpectedly.
- risk 0.35cvss 5.3epss 0.01
There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.35cvss 5.3epss 0.01
There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.
- risk 0.35cvss 5.3epss 0.01
There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.
- risk 0.35cvss 5.3epss 0.01
There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability may lead to low-sensitive information exposure.
- risk 0.35cvss 5.3epss 0.01
There is a heap-based buffer overflow vulnerability in some Huawei Smartphone, Successful exploit of this vulnerability can cause process exceptions during updating.
- risk 0.34cvss 5.3epss 0.00
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.
- risk 0.34cvss 5.3epss 0.01
There is an Out-of-bounds read vulnerability in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
Page 12 of 13