Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44550 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-44549 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality. | ||
| CVE-2022-44547 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability. | ||
| CVE-2022-44546 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart. | ||
| CVE-2021-46852 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-44556 | Hig | 0.49 | 7.5 | 0.00 | Nov 8, 2022 | Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2022-41589 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2022 | The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability. | ||
| CVE-2022-41588 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-41586 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-41583 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module. | ||
| CVE-2022-41582 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2022 | The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-39011 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module. | ||
| CVE-2022-38998 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality. | ||
| CVE-2022-38985 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38984 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality. | ||
| CVE-2022-38981 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage. | ||
| CVE-2022-38977 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data. | ||
| CVE-2022-37395 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2022 | A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS attacks.Affected product versions include:CV81-WDM FW versions 01.70.49.29.46. | ||
| CVE-2022-39010 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information. | ||
| CVE-2022-39005 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | ||
| CVE-2022-39004 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | ||
| CVE-2022-39001 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure. | ||
| CVE-2022-38997 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38996 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38995 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38994 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38993 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38992 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38991 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38990 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38989 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38988 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38987 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-38979 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-38978 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-46836 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40024 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40023 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2022 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality. | ||
| CVE-2020-36601 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot. | ||
| CVE-2020-36600 | Hig | 0.49 | 7.5 | 0.01 | Sep 16, 2022 | Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2022-37008 | Hig | 0.49 | 7.5 | 0.00 | Aug 10, 2022 | The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability. | ||
| CVE-2022-37007 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability. | ||
| CVE-2022-37006 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2022-37005 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-37004 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability. | ||
| CVE-2022-37001 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash. | ||
| CVE-2021-40040 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2021-40034 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability. | ||
| CVE-2021-40030 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-34743 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability. |
- risk 0.49cvss 7.5epss 0.00
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
- risk 0.49cvss 7.5epss 0.00
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.
- risk 0.49cvss 7.5epss 0.00
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart.
- risk 0.49cvss 7.5epss 0.00
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.01
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability.
- risk 0.49cvss 7.5epss 0.00
The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.
- risk 0.49cvss 7.5epss 0.01
The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.
- risk 0.49cvss 7.5epss 0.00
The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.
- risk 0.49cvss 7.5epss 0.00
The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.
- risk 0.49cvss 7.5epss 0.01
A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS attacks.Affected product versions include:CV81-WDM FW versions 01.70.49.29.46.
- risk 0.49cvss 7.5epss 0.01
The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information.
- risk 0.49cvss 7.5epss 0.01
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- risk 0.49cvss 7.5epss 0.01
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- risk 0.49cvss 7.5epss 0.01
The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality.
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.00
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
- risk 0.49cvss 7.5epss 0.01
The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.
- risk 0.49cvss 7.5epss 0.01
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
- risk 0.49cvss 7.5epss 0.01
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.
- risk 0.49cvss 7.5epss 0.01
The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.
- risk 0.49cvss 7.5epss 0.01
Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.01
The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability.
- risk 0.49cvss 7.5epss 0.01
The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
Page 16 of 48