Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0708 | Cri | 0.93 | 9.8 | 1.00 | KEV | May 16, 2019 | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution… | |
| CVE-2017-14491 | Cri | 0.73 | 9.8 | 0.85 | Oct 4, 2017 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | ||
| CVE-2019-2215 | Hig | 0.71 | 7.8 | 0.44 | KEV | Oct 11, 2019 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate… | |
| CVE-2017-17215 | Hig | 0.66 | 8.8 | 0.79 | Mar 20, 2018 | Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code. | ||
| CVE-2023-34157 | Cri | 0.65 | 10.0 | 0.00 | Jun 16, 2023 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | ||
| CVE-2022-32203 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2024 | There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE)… | ||
| CVE-2023-52381 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2024 | Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. | ||
| CVE-2023-52378 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2024 | Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-52370 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2024 | Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access. | ||
| CVE-2023-52103 | Cri | 0.64 | 9.8 | 0.00 | Jan 16, 2024 | Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read. | ||
| CVE-2023-46773 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2023-44116 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized. | ||
| CVE-2023-44105 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-44106 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2022-48605 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. | ||
| CVE-2023-41297 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking. | ||
| CVE-2023-41294 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. | ||
| CVE-2023-39405 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2023 | Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges. | ||
| CVE-2023-37242 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities. | ||
| CVE-2022-48513 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2022-48512 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally. | ||
| CVE-2022-48511 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally. | ||
| CVE-2022-48510 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations. | ||
| CVE-2021-46894 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation. | ||
| CVE-2021-46891 | Cri | 0.64 | 9.8 | 0.00 | Jul 5, 2023 | Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. | ||
| CVE-2021-46890 | Cri | 0.64 | 9.8 | 0.00 | Jul 5, 2023 | Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. | ||
| CVE-2023-34159 | Cri | 0.64 | 9.8 | 0.00 | Jun 19, 2023 | Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality. | ||
| CVE-2022-48472 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211. | ||
| CVE-2022-48479 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2022-48478 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2021-46887 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read. | ||
| CVE-2022-48353 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2023 | Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions. | ||
| CVE-2022-48284 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2023 | A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions. | ||
| CVE-2022-48283 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2023 | A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions. | ||
| CVE-2022-48259 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges. | ||
| CVE-2022-48255 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. | ||
| CVE-2022-46327 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions. | ||
| CVE-2022-46326 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46325 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46324 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46323 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46320 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting. | ||
| CVE-2022-46319 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write. | ||
| CVE-2022-46316 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | ||
| CVE-2022-44562 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2022-44559 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2022-44558 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2022-44551 | Cri | 0.64 | 9.8 | 0.00 | Nov 9, 2022 | The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. | ||
| CVE-2021-46851 | Cri | 0.64 | 9.8 | 0.00 | Nov 9, 2022 | The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback. | ||
| CVE-2022-41580 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. |
- risk 0.93cvss 9.8epss 1.00
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution…
- risk 0.73cvss 9.8epss 0.85
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
- risk 0.71cvss 7.8epss 0.44
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate…
- risk 0.66cvss 8.8epss 0.79
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.
- risk 0.65cvss 10.0epss 0.00
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
- risk 0.64cvss 9.8epss 0.01
There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE)…
- risk 0.64cvss 9.8epss 0.00
Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.
- risk 0.64cvss 9.8epss 0.00
Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.
- risk 0.64cvss 9.8epss 0.01
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
- risk 0.64cvss 9.8epss 0.00
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.64cvss 9.8epss 0.00
Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.
- risk 0.64cvss 9.8epss 0.00
Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.00
Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.
- risk 0.64cvss 9.8epss 0.01
A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions.
- risk 0.64cvss 9.8epss 0.00
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- risk 0.64cvss 9.8epss 0.00
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.
- risk 0.64cvss 9.8epss 0.01
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.
- risk 0.64cvss 9.8epss 0.01
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.64cvss 9.8epss 0.00
The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
- risk 0.64cvss 9.8epss 0.00
Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
- risk 0.64cvss 9.8epss 0.00
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- risk 0.64cvss 9.8epss 0.01
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.01
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.01
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.00
The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.00
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
- risk 0.64cvss 9.8epss 0.01
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Page 1 of 48