VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2020-1806HigApr 27, 2020
    risk 0.46cvss 7.1epss 0.01

    Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may…

  • CVE-2020-1805HigApr 27, 2020
    risk 0.46cvss 7.1epss 0.01

    Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may…

  • CVE-2020-1804HigApr 27, 2020
    risk 0.46cvss 7.1epss 0.01

    Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may…

  • CVE-2019-5216HigJun 6, 2019
    risk 0.46cvss 7.0epss 0.01

    There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C00E156R2P14T8), Honor 10 smartphones versions earlier than Columbia-AL10B 9.0.0.156(C00E156R1P20T8) and Honor Play smartphones versions earlier than…

  • CVE-2018-7921MedSep 12, 2018
    risk 0.46cvss 6.5epss 0.13

    Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this vulnerability to obtain device information.

  • CVE-2017-15309HigDec 22, 2017
    risk 0.46cvss 7.1epss 0.01

    Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.

  • CVE-2017-8153HigNov 22, 2017
    risk 0.46cvss 7.1epss 0.01

    Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScript code in web pages without obtaining…

  • CVE-2017-2735HigNov 22, 2017
    risk 0.46cvss 7.1epss 0.01

    TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability. The software provides a system interface for interaction with external applications, but calling the interface is not properly restricted. An attacker could…

  • CVE-2017-2707HigNov 22, 2017
    risk 0.46cvss 7.1epss 0.00

    Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to cause the attacker to delete message or fake user to send…

  • CVE-2017-2706HigNov 22, 2017
    risk 0.46cvss 7.1epss 0.01

    Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module. Since the system does not verify the file name during decompression, system directories are traversed. It could be exploited to cause the attacker to replace files and…

  • CVE-2015-4422HigOct 19, 2017
    risk 0.46cvss 7.0epss 0.01

    The TEEOS module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users with root permissions to gain privileges or cause a denial of service (memory corruption) via a crafted application.

  • CVE-2015-7842HigOct 10, 2017
    risk 0.46cvss 7.1epss 0.01

    Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with software before…

  • CVE-2016-8794HigApr 2, 2017
    risk 0.46cvss 7.1epss 0.01

    Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before…

  • CVE-2016-8792HigApr 2, 2017
    risk 0.46cvss 7.1epss 0.01

    Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before…

  • CVE-2016-8791HigApr 2, 2017
    risk 0.46cvss 7.1epss 0.01

    Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before…

  • CVE-2016-6179HigSep 7, 2016
    risk 0.46cvss 7.0epss 0.00

    The WiFi driver in Huawei Honor 6 smartphones with software H60-L01 before H60-L01C00B850, H60-L11 before H60-L11C00B850, H60-L21 before H60-L21C00B850, H60-L02 before H60-L02C00B850, H60-L12 before H60-L12C00B850, and H60-L03 before H60-L03C01B850 allows attackers to cause a…

  • CVE-2016-6184HigSep 7, 2016
    risk 0.46cvss 7.0epss 0.00

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted…

  • CVE-2016-6183HigSep 7, 2016
    risk 0.46cvss 7.0epss 0.00

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted…

  • CVE-2016-6182HigSep 7, 2016
    risk 0.46cvss 7.0epss 0.01

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted…

  • CVE-2016-6181HigSep 7, 2016
    risk 0.46cvss 7.0epss 0.00

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted…

  • CVE-2016-6180HigSep 7, 2016
    risk 0.46cvss 7.0epss 0.00

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted…

  • CVE-2015-8333HigJan 11, 2016
    risk 0.46cvss 7.1epss 0.01

    The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authenticated users to change the IP address of the media server via crafted packets.

  • CVE-2026-28553MedApr 13, 2026
    risk 0.45cvss 6.9epss 0.00

    Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-24922MedFeb 6, 2026
    risk 0.45cvss 6.9epss 0.00

    Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-53167MedJul 7, 2025
    risk 0.45cvss 6.9epss 0.00

    Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-42033MedAug 8, 2024
    risk 0.45cvss 6.9epss 0.00

    Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2026-41970MedMay 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-34864MedApr 13, 2026
    risk 0.44cvss 6.8epss 0.00

    Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-34863MedApr 13, 2026
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28547MedMar 5, 2026
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-24918MedFeb 6, 2026
    risk 0.44cvss 6.8epss 0.00

    Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68969MedJan 14, 2026
    risk 0.44cvss 6.8epss 0.00

    Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66326MedDec 8, 2025
    risk 0.44cvss 6.7epss 0.00

    Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58309MedNov 28, 2025
    risk 0.44cvss 6.8epss 0.00

    Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2025-58276MedSep 5, 2025
    risk 0.44cvss 6.8epss 0.00

    Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54642MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54641MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54633MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54632MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2025-54631MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Vulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54630MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54629MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2025-54625MedAug 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Race condition vulnerability in the kernel file system module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54617MedAug 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.

  • CVE-2025-48908MedJun 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-31174MedApr 7, 2025
    risk 0.44cvss 6.8epss 0.00

    Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-31171MedApr 7, 2025
    risk 0.44cvss 6.8epss 0.00

    File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-27521MedMar 4, 2025
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-58048MedMar 4, 2025
    risk 0.44cvss 6.7epss 0.00

    Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-57961MedFeb 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Page 25 of 48