Vendor CVEs
Huawei
All CVEs
2,254 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38996 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | |||
| CVE-2022-38995 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | |||
| CVE-2022-38994 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-38992 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-38991 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-38979 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-38978 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-38989 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | |||
| CVE-2022-38988 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-39005 | 0.00 | — | 0.01 | Sep 16, 2022 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | |||
| CVE-2022-39004 | 0.00 | — | 0.00 | Sep 16, 2022 | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. | |||
| CVE-2022-38987 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | |||
| CVE-2022-39006 | 0.00 | — | 0.00 | Sep 16, 2022 | The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart. | |||
| CVE-2022-38993 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | |||
| CVE-2022-38990 | 0.00 | — | 0.00 | Sep 16, 2022 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. | |||
| CVE-2022-39000 | 0.00 | — | 0.01 | Sep 16, 2022 | The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup. | |||
| CVE-2021-46836 | 0.00 | — | 0.00 | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2021-40024 | 0.00 | — | 0.00 | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-39008 | 0.00 | — | 0.01 | Sep 16, 2022 | The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps. | |||
| CVE-2021-40017 | 0.00 | — | 0.01 | Sep 16, 2022 | The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access. | |||
| CVE-2022-20255 | 0.00 | — | 0.00 | Aug 11, 2022 | In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | |||
| CVE-2021-40040 | 0.00 | — | 0.00 | Aug 9, 2022 | Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality. | |||
| CVE-2021-40030 | 0.00 | — | 0.00 | Aug 9, 2022 | The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-37005 | 0.00 | — | 0.00 | Aug 9, 2022 | The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-37003 | 0.00 | — | 0.00 | Aug 9, 2022 | The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files. | |||
| CVE-2022-37004 | 0.00 | — | 0.01 | Aug 9, 2022 | The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability. | |||
| CVE-2022-37002 | 0.00 | — | 0.00 | Aug 9, 2022 | The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background. | |||
| CVE-2022-37008 | 0.00 | — | 0.00 | Aug 9, 2022 | The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability. | |||
| CVE-2022-37001 | 0.00 | — | 0.00 | Aug 9, 2022 | The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash. | |||
| CVE-2022-37007 | 0.00 | — | 0.01 | Aug 9, 2022 | The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability. | |||
| CVE-2021-40034 | 0.00 | — | 0.01 | Aug 9, 2022 | The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability. | |||
| CVE-2020-14114 | 0.00 | — | 0.01 | Jul 22, 2022 | information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information. | |||
| CVE-2021-39999 | 0.00 | — | 0.01 | Jul 11, 2022 | There is a buffer overflow vulnerability in eSE620X vESS V100R001C10SPC200 and V100R001C20SPC200. An attacker can exploit this vulnerability by sending a specific message to the target device due to insufficient validation of packets. Successful exploit could cause a denial of… | |||
| CVE-2021-40016 | 0.00 | — | 0.00 | Jul 11, 2022 | Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality. | |||
| CVE-2021-40013 | 0.00 | — | 0.00 | Jul 11, 2022 | Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity. | |||
| CVE-2021-40012 | 0.00 | — | 0.01 | Jul 11, 2022 | Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality. | |||
| CVE-2022-34738 | 0.00 | — | 0.00 | Jul 11, 2022 | The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background. | |||
| CVE-2022-34737 | 0.00 | — | 0.01 | Jul 11, 2022 | The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality. | |||
| CVE-2022-34742 | 0.00 | — | 0.01 | Jul 11, 2022 | The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-34739 | 0.00 | — | 0.01 | Jul 11, 2022 | The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings. | |||
| CVE-2022-34741 | 0.00 | — | 0.00 | Jul 11, 2022 | The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation. | |||
| CVE-2022-34740 | 0.00 | — | 0.00 | Jul 11, 2022 | The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation. | |||
| CVE-2022-34743 | 0.00 | — | 0.01 | Jul 11, 2022 | The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability. | |||
| CVE-2022-34736 | 0.00 | — | 0.01 | Jul 11, 2022 | The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability. | |||
| CVE-2022-34735 | 0.00 | — | 0.01 | Jul 11, 2022 | The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability. | |||
| CVE-2021-46741 | 0.00 | — | 0.01 | Jul 11, 2022 | The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of this vulnerability may affect system integrity. | |||
| CVE-2021-41037 | 0.00 | — | 0.01 | Jul 8, 2022 | In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings… | |||
| CVE-2021-26638 | 0.00 | — | 0.03 | Jun 22, 2022 | Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control. | |||
| CVE-2022-22259 | 0.00 | — | 0.00 | Jun 13, 2022 | There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device. | |||
| CVE-2022-29797 | 0.00 | — | 0.01 | Jun 13, 2022 | There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation. |
- CVE-2022-38996Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-38995Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-38994Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-38992Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-38991Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-38979Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-38978Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-38989Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-38988Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-39005Sep 16, 2022risk 0.00cvss —epss 0.01
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- CVE-2022-39004Sep 16, 2022risk 0.00cvss —epss 0.00
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- CVE-2022-38987Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-39006Sep 16, 2022risk 0.00cvss —epss 0.00
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
- CVE-2022-38993Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-38990Sep 16, 2022risk 0.00cvss —epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-39000Sep 16, 2022risk 0.00cvss —epss 0.01
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
- CVE-2021-46836Sep 16, 2022risk 0.00cvss —epss 0.00
Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-40024Sep 16, 2022risk 0.00cvss —epss 0.00
Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-39008Sep 16, 2022risk 0.00cvss —epss 0.01
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.
- CVE-2021-40017Sep 16, 2022risk 0.00cvss —epss 0.01
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.
- CVE-2022-20255Aug 11, 2022risk 0.00cvss —epss 0.00
In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- CVE-2021-40040Aug 9, 2022risk 0.00cvss —epss 0.00
Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2021-40030Aug 9, 2022risk 0.00cvss —epss 0.00
The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-37005Aug 9, 2022risk 0.00cvss —epss 0.00
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-37003Aug 9, 2022risk 0.00cvss —epss 0.00
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
- CVE-2022-37004Aug 9, 2022risk 0.00cvss —epss 0.01
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.
- CVE-2022-37002Aug 9, 2022risk 0.00cvss —epss 0.00
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
- CVE-2022-37008Aug 9, 2022risk 0.00cvss —epss 0.00
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
- CVE-2022-37001Aug 9, 2022risk 0.00cvss —epss 0.00
The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.
- CVE-2022-37007Aug 9, 2022risk 0.00cvss —epss 0.01
The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.
- CVE-2021-40034Aug 9, 2022risk 0.00cvss —epss 0.01
The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability.
- CVE-2020-14114Jul 22, 2022risk 0.00cvss —epss 0.01
information leakage vulnerability exists in the Xiaomi SmartHome APP. This vulnerability is caused by illegal calls of some sensitive JS interfaces, which can be exploited by attackers to leak sensitive information.
- CVE-2021-39999Jul 11, 2022risk 0.00cvss —epss 0.01
There is a buffer overflow vulnerability in eSE620X vESS V100R001C10SPC200 and V100R001C20SPC200. An attacker can exploit this vulnerability by sending a specific message to the target device due to insufficient validation of packets. Successful exploit could cause a denial of…
- CVE-2021-40016Jul 11, 2022risk 0.00cvss —epss 0.00
Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality.
- CVE-2021-40013Jul 11, 2022risk 0.00cvss —epss 0.00
Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity.
- CVE-2021-40012Jul 11, 2022risk 0.00cvss —epss 0.01
Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2022-34738Jul 11, 2022risk 0.00cvss —epss 0.00
The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background.
- CVE-2022-34737Jul 11, 2022risk 0.00cvss —epss 0.01
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
- CVE-2022-34742Jul 11, 2022risk 0.00cvss —epss 0.01
The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-34739Jul 11, 2022risk 0.00cvss —epss 0.01
The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings.
- CVE-2022-34741Jul 11, 2022risk 0.00cvss —epss 0.00
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
- CVE-2022-34740Jul 11, 2022risk 0.00cvss —epss 0.00
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
- CVE-2022-34743Jul 11, 2022risk 0.00cvss —epss 0.01
The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-34736Jul 11, 2022risk 0.00cvss —epss 0.01
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
- CVE-2022-34735Jul 11, 2022risk 0.00cvss —epss 0.01
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
- CVE-2021-46741Jul 11, 2022risk 0.00cvss —epss 0.01
The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of this vulnerability may affect system integrity.
- CVE-2021-41037Jul 8, 2022risk 0.00cvss —epss 0.01
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings…
- CVE-2021-26638Jun 22, 2022risk 0.00cvss —epss 0.03
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control.
- CVE-2022-22259Jun 13, 2022risk 0.00cvss —epss 0.00
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device.
- CVE-2022-29797Jun 13, 2022risk 0.00cvss —epss 0.01
There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation.
Page 30 of 46