VYPR

Vendor CVEs

Huawei

All CVEs

2,397 total · sorted by risk
  • CVE-2024-12602MedFeb 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54121MedJan 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-56443MedJan 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-56440MedJan 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-52953MedJan 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-56435MedJan 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54122MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-54119MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54117MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54110MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54104MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54103MedDec 12, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54102MedDec 12, 2024
    risk 0.40cvss 6.1epss 0.00

    Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54101MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-54100MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-51525MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-51522MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of improper device information processing in the device management module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-51516MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormally.

  • CVE-2024-51515MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-51512MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-51511MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-47292MedSep 27, 2024
    risk 0.40cvss 6.2epss 0.00

    Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-8298MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-45443MedSep 4, 2024
    risk 0.40cvss 6.1epss 0.01

    Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2024-45441MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-42030MedAug 8, 2024
    risk 0.40cvss 6.2epss 0.00

    Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-39674MedJul 25, 2024
    risk 0.40cvss 6.2epss 0.00

    Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-39670MedJul 25, 2024
    risk 0.40cvss 6.2epss 0.00

    Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32996MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32995MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32990MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52721MedMay 14, 2024
    risk 0.40cvss 6.2epss 0.00

    The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-52385MedApr 8, 2024
    risk 0.40cvss 6.2epss 0.00

    Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52543MedApr 8, 2024
    risk 0.40cvss 6.2epss 0.00

    Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52358MedFeb 18, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of configuration defects in some APIs of the audio module.Successful exploitation of this vulnerability may affect availability.

  • CVE-2020-36602MedSep 20, 2022
    risk 0.40cvss 6.1epss 0.00

    There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message,…

  • CVE-2020-9119MedDec 24, 2020
    risk 0.40cvss 6.2epss 0.00

    There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute relevant commands, resulting in the user's privilege promotion.

  • CVE-2020-1855MedFeb 18, 2020
    risk 0.40cvss 6.1epss 0.00

    Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the device physically and exploit this vulnerability to tamper with device…

  • CVE-2019-5246MedNov 13, 2019
    risk 0.40cvss 6.2epss 0.00

    Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does…

  • CVE-2019-5229MedNov 12, 2019
    risk 0.40cvss 6.2epss 0.00

    P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack,…

  • CVE-2019-5286MedJun 13, 2019
    risk 0.40cvss 6.1epss 0.01

    There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.

  • CVE-2018-7940MedMay 10, 2018
    risk 0.40cvss 6.2epss 0.00

    Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some…

  • CVE-2017-8215MedNov 22, 2017
    risk 0.40cvss 6.2epss 0.00

    Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions…

  • CVE-2017-8214MedNov 22, 2017
    risk 0.40cvss 6.2epss 0.00

    Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions…

  • CVE-2017-8182MedNov 22, 2017
    risk 0.40cvss 6.1epss 0.01

    MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given…

  • CVE-2017-8139MedNov 22, 2017
    risk 0.40cvss 6.1epss 0.01

    HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to interrupt the services of legitimate users.

  • CVE-2017-8127MedNov 22, 2017
    risk 0.40cvss 6.1epss 0.01

    The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.

  • CVE-2017-8125MedNov 22, 2017
    risk 0.40cvss 6.1epss 0.01

    The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.

  • CVE-2016-8789MedApr 2, 2017
    risk 0.40cvss 6.1epss 0.01

    Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.

  • CVE-2016-6840MedSep 26, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName parameter to cgi-bin/doLogin_CgiEntry and possibly other unspecified vectors.

Page 31 of 48