VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2023-26548HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.01

    The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.

  • CVE-2022-48360HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-48359HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-48357HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.

  • CVE-2022-48356HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition.

  • CVE-2022-48352HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.

  • CVE-2022-48351HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.

  • CVE-2022-48350HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-48347HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-48346HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-48261HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.00

    There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation of this vulnerability may cause the printer service to be abnormal.

  • CVE-2022-48260HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.00

    There is a buffer overflow vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to device service exceptions.

  • CVE-2022-48230HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.00

    There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to DoS.

  • CVE-2022-48302HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48301HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.

  • CVE-2022-48300HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48299HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48298HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.

  • CVE-2022-48297HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.

  • CVE-2022-48295HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).

  • CVE-2022-48294HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48289HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48288HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-48287HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2022-48286HigFeb 9, 2023
    risk 0.49cvss 7.5epss 0.00

    The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-47976HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.

  • CVE-2022-47975HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.01

    The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-46762HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-46761HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.

  • CVE-2021-46868HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.

  • CVE-2021-46867HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.

  • CVE-2022-39012HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Huawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application service abnormal.

  • CVE-2022-46328HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-46322HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.

  • CVE-2022-46321HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-46317HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-46315HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-46314HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-46312HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.

  • CVE-2022-46311HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2022-46310HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-41599HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-41596HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.

  • CVE-2022-41591HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.

  • CVE-2021-46856HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-44561HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.

  • CVE-2022-44557HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-44555HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.

  • CVE-2022-44554HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.

  • CVE-2022-44552HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

Page 15 of 48