Magic UI
by Huawei
CVEs (253)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22351 | Hig | 0.53 | 8.1 | 0.01 | Jun 30, 2021 | There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may induce users to grant permissions on modifying items in the configuration table,causing system exceptions. | ||
| CVE-2021-22369 | Hig | 0.53 | 8.1 | 0.01 | Jun 30, 2021 | There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user. | ||
| CVE-2022-31762 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2022 | The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2021-36999 | Hig | 0.51 | 7.8 | 0.01 | Oct 28, 2021 | There is a Buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by sending malicious images and inducing users to open the images may cause remote code execution. | ||
| CVE-2021-22385 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2021 | A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution. | ||
| CVE-2021-22352 | Hig | 0.51 | 7.8 | 0.00 | Jun 30, 2021 | There is a Configuration Defect Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands. | ||
| CVE-2021-22335 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2021 | There is a Memory Buffer Improper Operation Limit vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause exceptions in image processing. | ||
| CVE-2020-9147 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2021 | A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read. | ||
| CVE-2022-39005 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | ||
| CVE-2022-39004 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | ||
| CVE-2022-39001 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure. | ||
| CVE-2022-38997 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38990 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38989 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38979 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38978 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2020-36601 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot. | ||
| CVE-2020-36600 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2022-37008 | Hig | 0.49 | 7.5 | 0.00 | Aug 10, 2022 | The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability. | ||
| CVE-2022-37007 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability. |
- risk 0.53cvss 8.1epss 0.01
There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may induce users to grant permissions on modifying items in the configuration table,causing system exceptions.
- risk 0.53cvss 8.1epss 0.01
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.
- risk 0.51cvss 7.8epss 0.00
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.51cvss 7.8epss 0.01
There is a Buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by sending malicious images and inducing users to open the images may cause remote code execution.
- risk 0.51cvss 7.8epss 0.00
A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
- risk 0.51cvss 7.8epss 0.00
There is a Configuration Defect Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.
- risk 0.51cvss 7.8epss 0.00
There is a Memory Buffer Improper Operation Limit vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause exceptions in image processing.
- risk 0.51cvss 7.8epss 0.00
A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read.
- risk 0.49cvss 7.5epss 0.01
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- risk 0.49cvss 7.5epss 0.01
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- risk 0.49cvss 7.5epss 0.01
The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.00
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
- risk 0.49cvss 7.5epss 0.01
The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.
Page 4 of 13