Vendor CVEs
Huawei
All CVEs
2,397 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56436 | Med | 0.36 | 5.5 | 0.00 | Jan 8, 2025 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54112 | Med | 0.36 | 5.5 | 0.00 | Dec 12, 2024 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-51529 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2024-51520 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51513 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption. | ||
| CVE-2024-47291 | Med | 0.36 | 5.6 | 0.00 | Sep 27, 2024 | Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-47290 | Med | 0.36 | 5.5 | 0.00 | Sep 27, 2024 | Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-45446 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2024 | Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-45444 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2024 | Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-7271 | Med | 0.36 | 5.5 | 0.00 | Jul 25, 2024 | Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-40575 | Med | 0.36 | 5.5 | 0.00 | Jul 24, 2024 | An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification of table attributes | ||
| CVE-2024-36501 | Med | 0.36 | 5.6 | 0.00 | Jun 14, 2024 | Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity. | ||
| CVE-2024-32993 | Med | 0.36 | 5.6 | 0.00 | May 14, 2024 | Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-49248 | Med | 0.36 | 5.5 | 0.00 | Dec 6, 2023 | Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access. | ||
| CVE-2022-48518 | Med | 0.36 | 5.5 | 0.00 | Jul 6, 2023 | Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the… | ||
| CVE-2022-48305 | Med | 0.36 | 5.5 | 0.00 | Feb 27, 2023 | There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail. | ||
| CVE-2022-45874 | Med | 0.36 | 5.5 | 0.00 | Dec 28, 2022 | Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file. | ||
| CVE-2022-41590 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2022 | Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability. | ||
| CVE-2021-46834 | Med | 0.36 | 5.5 | 0.00 | Sep 20, 2022 | A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4). | ||
| CVE-2022-31752 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality. | ||
| CVE-2022-31763 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-31759 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-31756 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-31755 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-31751 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2022 | The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2021-37103 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2022 | There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-22479 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2022 | The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash. | ||
| CVE-2021-22478 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2022 | The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage. | ||
| CVE-2021-22441 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2022 | Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to kernel crash. | ||
| CVE-2021-40045 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-39991 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-39986 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-37115 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-37107 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | There is an improper memory access permission configuration on ACPU.Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2021-40033 | Med | 0.36 | 5.5 | 0.00 | Jan 31, 2022 | There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software does not properly protect certain information. Successful exploit could cause information disclosure. Affected product versions include: CloudEngine 12800… | ||
| CVE-2021-40037 | Med | 0.36 | 5.5 | 0.00 | Jan 10, 2022 | There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart. | ||
| CVE-2021-37036 | Med | 0.36 | 5.5 | 0.00 | Nov 23, 2021 | There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may… | ||
| CVE-2021-22471 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash. | ||
| CVE-2021-22467 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address. | ||
| CVE-2021-22466 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash. | ||
| CVE-2021-22465 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable. | ||
| CVE-2021-22463 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure. | ||
| CVE-2021-22462 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash. | ||
| CVE-2021-22461 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash. | ||
| CVE-2021-22460 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism. | ||
| CVE-2021-22459 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable. | ||
| CVE-2021-22456 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable. | ||
| CVE-2021-22455 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released. | ||
| CVE-2021-22454 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump. | ||
| CVE-2021-22452 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address. |
- risk 0.36cvss 5.5epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.
- risk 0.36cvss 5.6epss 0.00
Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.36cvss 5.5epss 0.00
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.36cvss 5.5epss 0.00
An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification of table attributes
- risk 0.36cvss 5.6epss 0.00
Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.
- risk 0.36cvss 5.6epss 0.00
Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the…
- risk 0.36cvss 5.5epss 0.00
There is an identity authentication bypass vulnerability in Huawei Children Smart Watch (Simba-AL00) 1.1.1.274. Successful exploitation of this vulnerability may cause the access control function of specific applications to fail.
- risk 0.36cvss 5.5epss 0.00
Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file.
- risk 0.36cvss 5.5epss 0.00
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
- risk 0.36cvss 5.5epss 0.00
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).
- risk 0.36cvss 5.5epss 0.00
Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.
- risk 0.36cvss 5.5epss 0.00
The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.
- risk 0.36cvss 5.5epss 0.00
AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability.
- risk 0.36cvss 5.5epss 0.00
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.36cvss 5.5epss 0.00
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
- risk 0.36cvss 5.5epss 0.00
The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.
- risk 0.36cvss 5.5epss 0.00
There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.
- risk 0.36cvss 5.5epss 0.00
The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage.
- risk 0.36cvss 5.5epss 0.00
Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.
- risk 0.36cvss 5.5epss 0.00
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
There is an improper memory access permission configuration on ACPU.Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.36cvss 5.5epss 0.00
There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software does not properly protect certain information. Successful exploit could cause information disclosure. Affected product versions include: CloudEngine 12800…
- risk 0.36cvss 5.5epss 0.00
There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.
- risk 0.36cvss 5.5epss 0.00
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may…
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
Page 34 of 48