VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2024-45446MedSep 4, 2024
    risk 0.36cvss 5.5epss 0.00

    Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-45444MedSep 4, 2024
    risk 0.36cvss 5.5epss 0.00

    Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-7271MedJul 25, 2024
    risk 0.36cvss 5.5epss 0.00

    Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-40575MedJul 24, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification of table attributes

  • CVE-2024-36501MedJun 14, 2024
    risk 0.36cvss 5.6epss 0.00

    Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.

  • CVE-2024-32993MedMay 14, 2024
    risk 0.36cvss 5.6epss 0.00

    Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-49248MedDec 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.

  • CVE-2022-48518MedJul 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the…

  • CVE-2022-48305MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail.

  • CVE-2022-45874MedDec 28, 2022
    risk 0.36cvss 5.5epss 0.00

    Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file.

  • CVE-2022-41590MedDec 20, 2022
    risk 0.36cvss 5.5epss 0.00

    Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.

  • CVE-2021-46834MedSep 20, 2022
    risk 0.36cvss 5.5epss 0.00

    A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).

  • CVE-2022-31752MedJun 13, 2022
    risk 0.36cvss 5.5epss 0.00

    Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.

  • CVE-2022-31763MedJun 13, 2022
    risk 0.36cvss 5.5epss 0.00

    The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-31759MedJun 13, 2022
    risk 0.36cvss 5.5epss 0.00

    AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-31756MedJun 13, 2022
    risk 0.36cvss 5.5epss 0.00

    The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-31755MedJun 13, 2022
    risk 0.36cvss 5.5epss 0.00

    The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-31751MedJun 13, 2022
    risk 0.36cvss 5.5epss 0.00

    The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2021-37103MedFeb 25, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22479MedFeb 25, 2022
    risk 0.36cvss 5.5epss 0.00

    The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.

  • CVE-2021-22478MedFeb 25, 2022
    risk 0.36cvss 5.5epss 0.00

    The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage.

  • CVE-2021-22441MedFeb 25, 2022
    risk 0.36cvss 5.5epss 0.00

    Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.

  • CVE-2021-40045MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-39991MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-39986MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37115MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37107MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an improper memory access permission configuration on ACPU.Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-40033MedJan 31, 2022
    risk 0.36cvss 5.5epss 0.00

    There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software does not properly protect certain information. Successful exploit could cause information disclosure. Affected product versions include: CloudEngine 12800…

  • CVE-2021-40037MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.00

    There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.

  • CVE-2021-37036MedNov 23, 2021
    risk 0.36cvss 5.5epss 0.00

    There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may…

  • CVE-2021-22471MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.

  • CVE-2021-22467MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.

  • CVE-2021-22466MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.

  • CVE-2021-22465MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.

  • CVE-2021-22463MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.

  • CVE-2021-22462MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.

  • CVE-2021-22461MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.

  • CVE-2021-22460MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism.

  • CVE-2021-22459MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable.

  • CVE-2021-22456MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.

  • CVE-2021-22455MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released.

  • CVE-2021-22454MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.

  • CVE-2021-22452MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.

  • CVE-2021-22450MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.

  • CVE-2021-22295MedAug 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

  • CVE-2021-22424MedAug 3, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.

  • CVE-2021-22419MedAug 3, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.

  • CVE-2021-22417MedAug 3, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.

  • CVE-2021-22400MedAug 3, 2021
    risk 0.36cvss 5.5epss 0.00

    Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The app can modify specific parameters, causing the system to crash. Affected product…

  • CVE-2021-22318MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service.

Page 34 of 48