Vendor CVEs
Huawei
All CVEs
2,397 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-8178 | Med | 0.35 | 5.4 | 0.01 | Nov 22, 2017 | Huawei Email APP Vicky-AL00 smartphones with software of earlier than VKY-AL00C00B171 versions has a stored cross-site scripting vulnerability. A remote attacker could exploit this vulnerability to send email that storing malicious code to a smartphone and waiting for a user to… | ||
| CVE-2017-8121 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2017 | The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak. | ||
| CVE-2017-2720 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2017 | FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages between certain components, which significantly increases the possibility that encrypted data may be recovered and results in… | ||
| CVE-2017-2713 | Med | 0.35 | 5.4 | 0.00 | Nov 22, 2017 | HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09C432B370, versions earlier before VIE-L29C636B370 have an insufficient input validation vulnerability. An attacker could exploit… | ||
| CVE-2017-2712 | Med | 0.35 | 5.3 | 0.01 | Nov 22, 2017 | S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed packets and send them to a device to cause EFM flapping. | ||
| CVE-2016-4058 | Med | 0.35 | 5.4 | 0.01 | Sep 27, 2016 | Cross-site scripting (XSS) vulnerability in Huawei Policy Center before V100R003C10SPC020 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to "special characters on pages." | ||
| CVE-2016-6670 | Med | 0.35 | 5.3 | 0.01 | Sep 7, 2016 | Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate. | ||
| CVE-2016-5850 | Med | 0.35 | 5.4 | 0.01 | Jul 12, 2016 | Cross-site scripting (XSS) vulnerability in the volume backup service module in Huawei Public Cloud Solution before 1.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2015-8672 | Med | 0.35 | 5.3 | 0.01 | Jan 12, 2016 | The presentation transmission permission management mechanism in Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 allows remote attackers to cause a denial of service (wired presentation outage) via unspecified… | ||
| CVE-2026-81647 | Med | 0.34 | 5.3 | 0.00 | Sep 9, 2026 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-41984 | Med | 0.34 | 5.2 | 0.00 | Jun 9, 2026 | UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2026-41981 | Med | 0.34 | 5.3 | 0.00 | Jun 9, 2026 | Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-66323 | Med | 0.34 | 5.3 | 0.00 | Dec 8, 2025 | Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-64313 | Med | 0.34 | 5.3 | 0.00 | Nov 28, 2025 | Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58285 | Med | 0.34 | 5.3 | 0.00 | Oct 11, 2025 | Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54628 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-54621 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures. | ||
| CVE-2025-54619 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability. | ||
| CVE-2025-53173 | Med | 0.34 | 5.3 | 0.00 | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function. | ||
| CVE-2024-58113 | Med | 0.34 | 5.3 | 0.00 | Apr 7, 2025 | Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2020-9085 | Med | 0.34 | 5.3 | 0.00 | Dec 27, 2024 | There is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affected products. Due to insufficient validation of some parameter in the message, successful exploit may cause some process abnormal.… | ||
| CVE-2024-54096 | Med | 0.34 | 5.3 | 0.00 | Dec 12, 2024 | Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy. | ||
| CVE-2024-51518 | Med | 0.34 | 5.3 | 0.00 | Nov 5, 2024 | Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51514 | Med | 0.34 | 5.3 | 0.00 | Nov 5, 2024 | Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52551 | Med | 0.34 | 5.3 | 0.00 | Apr 8, 2024 | Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52717 | Med | 0.34 | 5.3 | 0.00 | Apr 7, 2024 | Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52368 | Med | 0.34 | 5.3 | 0.00 | Feb 18, 2024 | Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-52365 | Med | 0.34 | 5.3 | 0.00 | Feb 18, 2024 | Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-52363 | Med | 0.34 | 5.3 | 0.00 | Feb 18, 2024 | Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by mistake. | ||
| CVE-2023-52112 | Med | 0.34 | 5.3 | 0.00 | Jan 16, 2024 | Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-6273 | Med | 0.34 | 5.3 | 0.00 | Dec 6, 2023 | Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-46756 | Med | 0.34 | 5.3 | 0.00 | Nov 8, 2023 | Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows. | ||
| CVE-2023-46764 | Med | 0.34 | 5.3 | 0.00 | Nov 8, 2023 | Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously. | ||
| CVE-2023-46763 | Med | 0.34 | 5.3 | 0.00 | Nov 8, 2023 | Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously. | ||
| CVE-2023-46755 | Med | 0.34 | 5.3 | 0.00 | Nov 8, 2023 | Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart. | ||
| CVE-2023-44102 | Med | 0.34 | 5.3 | 0.00 | Oct 11, 2023 | Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable. | ||
| CVE-2023-41304 | Med | 0.34 | 5.3 | 0.00 | Oct 11, 2023 | Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window. | ||
| CVE-2023-44094 | Med | 0.34 | 5.3 | 0.00 | Oct 11, 2023 | Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-4565 | Med | 0.34 | 5.3 | 0.00 | Sep 27, 2023 | Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable. | ||
| CVE-2023-41312 | Med | 0.34 | 5.3 | 0.00 | Sep 27, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically. | ||
| CVE-2023-41311 | Med | 0.34 | 5.3 | 0.00 | Sep 27, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically. | ||
| CVE-2023-41295 | Med | 0.34 | 5.3 | 0.00 | Sep 25, 2023 | Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim. | ||
| CVE-2023-39387 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2023 | Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows. | ||
| CVE-2023-3456 | Med | 0.34 | 5.3 | 0.00 | Jul 6, 2023 | Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-37238 | Med | 0.34 | 5.3 | 0.00 | Jul 6, 2023 | Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features. | ||
| CVE-2023-34167 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | ||
| CVE-2023-34160 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | ||
| CVE-2023-34158 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | ||
| CVE-2023-34156 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied. | ||
| CVE-2022-48495 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained. |
- risk 0.35cvss 5.4epss 0.01
Huawei Email APP Vicky-AL00 smartphones with software of earlier than VKY-AL00C00B171 versions has a stored cross-site scripting vulnerability. A remote attacker could exploit this vulnerability to send email that storing malicious code to a smartphone and waiting for a user to…
- risk 0.35cvss 5.3epss 0.01
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
- risk 0.35cvss 5.3epss 0.01
FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages between certain components, which significantly increases the possibility that encrypted data may be recovered and results in…
- risk 0.35cvss 5.4epss 0.00
HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09C432B370, versions earlier before VIE-L29C636B370 have an insufficient input validation vulnerability. An attacker could exploit…
- risk 0.35cvss 5.3epss 0.01
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed packets and send them to a device to cause EFM flapping.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in Huawei Policy Center before V100R003C10SPC020 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to "special characters on pages."
- risk 0.35cvss 5.3epss 0.01
Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in the volume backup service module in Huawei Public Cloud Solution before 1.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.35cvss 5.3epss 0.01
The presentation transmission permission management mechanism in Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 allows remote attackers to cause a denial of service (wired presentation outage) via unspecified…
- risk 0.34cvss 5.3epss 0.00
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.2epss 0.00
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
- risk 0.34cvss 5.3epss 0.00
Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.
- risk 0.34cvss 5.3epss 0.00
Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.
- risk 0.34cvss 5.3epss 0.00
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
There is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affected products. Due to insufficient validation of some parameter in the message, successful exploit may cause some process abnormal.…
- risk 0.34cvss 5.3epss 0.00
Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.34cvss 5.3epss 0.00
Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.34cvss 5.3epss 0.00
Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.34cvss 5.3epss 0.00
Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by mistake.
- risk 0.34cvss 5.3epss 0.00
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.34cvss 5.3epss 0.00
Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.34cvss 5.3epss 0.00
Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
- risk 0.34cvss 5.3epss 0.00
Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
- risk 0.34cvss 5.3epss 0.00
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.
- risk 0.34cvss 5.3epss 0.00
Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.
- risk 0.34cvss 5.3epss 0.00
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.34cvss 5.3epss 0.00
Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable.
- risk 0.34cvss 5.3epss 0.00
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
- risk 0.34cvss 5.3epss 0.00
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of permission control in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained.
Page 39 of 48