Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-26548 | Hig | 0.49 | 7.5 | 0.01 | Mar 27, 2023 | The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2022-48360 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48359 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48357 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel. | ||
| CVE-2022-48356 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition. | ||
| CVE-2022-48352 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic. | ||
| CVE-2022-48351 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2022-48350 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48347 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48346 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48261 | Hig | 0.49 | 7.5 | 0.00 | Feb 27, 2023 | There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation of this vulnerability may cause the printer service to be abnormal. | ||
| CVE-2022-48260 | Hig | 0.49 | 7.5 | 0.00 | Feb 27, 2023 | There is a buffer overflow vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to device service exceptions. | ||
| CVE-2022-48230 | Hig | 0.49 | 7.5 | 0.00 | Feb 27, 2023 | There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to DoS. | ||
| CVE-2022-48302 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48301 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled. | ||
| CVE-2022-48300 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48299 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48298 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. | ||
| CVE-2022-48297 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. | ||
| CVE-2022-48295 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications). | ||
| CVE-2022-48294 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48289 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48288 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48287 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-48286 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-47976 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections. | ||
| CVE-2022-47975 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2023 | The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46762 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-46761 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons. | ||
| CVE-2021-46868 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access. | ||
| CVE-2021-46867 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access. | ||
| CVE-2022-39012 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2022 | Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application service abnormal. | ||
| CVE-2022-46328 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-46322 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46321 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-46317 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46315 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46314 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46312 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications. | ||
| CVE-2022-46311 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-46310 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-41599 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-41596 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components. | ||
| CVE-2022-41591 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files. | ||
| CVE-2021-46856 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-44561 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction. | ||
| CVE-2022-44557 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-44555 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable. | ||
| CVE-2022-44554 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device. | ||
| CVE-2022-44552 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. |
- risk 0.49cvss 7.5epss 0.01
The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.
- risk 0.49cvss 7.5epss 0.00
The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition.
- risk 0.49cvss 7.5epss 0.00
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation of this vulnerability may cause the printer service to be abnormal.
- risk 0.49cvss 7.5epss 0.00
There is a buffer overflow vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to device service exceptions.
- risk 0.49cvss 7.5epss 0.00
There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to DoS.
- risk 0.49cvss 7.5epss 0.00
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.
- risk 0.49cvss 7.5epss 0.00
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.00
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.00
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).
- risk 0.49cvss 7.5epss 0.00
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.
- risk 0.49cvss 7.5epss 0.01
The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.
- risk 0.49cvss 7.5epss 0.00
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.00
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.01
Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application service abnormal.
- risk 0.49cvss 7.5epss 0.00
Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.49cvss 7.5epss 0.00
The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.
- risk 0.49cvss 7.5epss 0.00
The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.
- risk 0.49cvss 7.5epss 0.01
The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.
- risk 0.49cvss 7.5epss 0.01
The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
- risk 0.49cvss 7.5epss 0.00
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
- risk 0.49cvss 7.5epss 0.00
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
- risk 0.49cvss 7.5epss 0.00
The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
Page 15 of 48