Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-34865 | Cri | 0.59 | 9.1 | 0.00 | Apr 13, 2026 | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2023-52538 | Cri | 0.59 | 9.1 | 0.00 | Apr 8, 2024 | Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-30415 | Cri | 0.59 | 9.1 | 0.00 | Apr 7, 2024 | Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52369 | Cri | 0.59 | 9.1 | 0.00 | Feb 18, 2024 | Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-52101 | Cri | 0.59 | 9.1 | 0.00 | Jan 16, 2024 | Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-5801 | Cri | 0.59 | 9.1 | 0.00 | Nov 8, 2023 | Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality. | ||
| CVE-2023-44118 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2023-44107 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-41296 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality. | ||
| CVE-2023-39407 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2023-39403 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39402 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39401 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39400 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39399 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39398 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39385 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access. | ||
| CVE-2021-46895 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop. | ||
| CVE-2023-37245 | Cri | 0.59 | 9.1 | 0.00 | Jul 6, 2023 | Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem. | ||
| CVE-2023-37240 | Cri | 0.59 | 9.1 | 0.00 | Jul 6, 2023 | Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read. | ||
| CVE-2023-3455 | Cri | 0.59 | 9.1 | 0.00 | Jul 5, 2023 | Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2022-48312 | Cri | 0.59 | 9.1 | 0.00 | Apr 16, 2023 | The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2022-48349 | Cri | 0.59 | 9.1 | 0.00 | Mar 27, 2023 | The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability. | ||
| CVE-2022-48348 | Cri | 0.59 | 9.1 | 0.00 | Mar 27, 2023 | The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2022-48290 | Cri | 0.59 | 9.1 | 0.00 | Feb 9, 2023 | The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity. | ||
| CVE-2022-41581 | Cri | 0.59 | 9.1 | 0.00 | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | ||
| CVE-2022-38986 | Cri | 0.59 | 9.1 | 0.01 | Oct 14, 2022 | The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability. | ||
| CVE-2021-46840 | Cri | 0.59 | 9.1 | 0.00 | Oct 14, 2022 | The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | ||
| CVE-2021-46839 | Cri | 0.59 | 9.1 | 0.00 | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | ||
| CVE-2022-39008 | Cri | 0.59 | 9.1 | 0.01 | Sep 16, 2022 | The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps. | ||
| CVE-2022-39003 | Cri | 0.59 | 9.1 | 0.00 | Sep 16, 2022 | Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components. | ||
| CVE-2021-40019 | Cri | 0.59 | 9.1 | 0.01 | Sep 16, 2022 | Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2022-34737 | Cri | 0.59 | 9.1 | 0.01 | Jul 12, 2022 | The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality. | ||
| CVE-2022-31760 | Cri | 0.59 | 9.1 | 0.01 | Jun 13, 2022 | Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality. | ||
| CVE-2022-22260 | Cri | 0.59 | 9.1 | 0.01 | May 13, 2022 | The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability. | ||
| CVE-2021-46742 | Cri | 0.59 | 9.1 | 0.01 | Apr 11, 2022 | The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability. | ||
| CVE-2021-40053 | Cri | 0.59 | 9.1 | 0.01 | Mar 10, 2022 | There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity. | ||
| CVE-2021-22448 | Cri | 0.59 | 9.1 | 0.01 | Feb 25, 2022 | There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files. | ||
| CVE-2021-22394 | Cri | 0.59 | 9.1 | 0.01 | Feb 25, 2022 | There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration. | ||
| CVE-2021-39982 | Cri | 0.59 | 9.1 | 0.01 | Jan 3, 2022 | Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications. | ||
| CVE-2021-37116 | Cri | 0.59 | 9.1 | 0.01 | Jan 3, 2022 | PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed. | ||
| CVE-2021-37051 | Cri | 0.59 | 9.1 | 0.01 | Dec 8, 2021 | There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access. | ||
| CVE-2021-37099 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file. | ||
| CVE-2021-37088 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can write any content to any file. | ||
| CVE-2021-37087 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create arbitrary file. | ||
| CVE-2021-37079 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission. | ||
| CVE-2021-37065 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted. | ||
| CVE-2021-37064 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to arbitrary file created. | ||
| CVE-2021-37062 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory overflow and information leakage. | ||
| CVE-2021-37021 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read. |
- risk 0.59cvss 9.1epss 0.00
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.59cvss 9.1epss 0.00
Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
- risk 0.59cvss 9.1epss 0.00
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.
- risk 0.59cvss 9.1epss 0.00
Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read.
- risk 0.59cvss 9.1epss 0.00
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.59cvss 9.1epss 0.00
The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability.
- risk 0.59cvss 9.1epss 0.00
The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.59cvss 9.1epss 0.00
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity.
- risk 0.59cvss 9.1epss 0.00
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
- risk 0.59cvss 9.1epss 0.01
The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.
- risk 0.59cvss 9.1epss 0.00
The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
- risk 0.59cvss 9.1epss 0.00
The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
- risk 0.59cvss 9.1epss 0.01
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.
- risk 0.59cvss 9.1epss 0.00
Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components.
- risk 0.59cvss 9.1epss 0.01
Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.59cvss 9.1epss 0.01
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
- risk 0.59cvss 9.1epss 0.01
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
- risk 0.59cvss 9.1epss 0.01
The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.
- risk 0.59cvss 9.1epss 0.01
The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
- risk 0.59cvss 9.1epss 0.01
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
- risk 0.59cvss 9.1epss 0.01
There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files.
- risk 0.59cvss 9.1epss 0.01
There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration.
- risk 0.59cvss 9.1epss 0.01
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.
- risk 0.59cvss 9.1epss 0.01
PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.
- risk 0.59cvss 9.1epss 0.01
There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- risk 0.59cvss 9.1epss 0.01
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file.
- risk 0.59cvss 9.1epss 0.01
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can write any content to any file.
- risk 0.59cvss 9.1epss 0.01
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create arbitrary file.
- risk 0.59cvss 9.1epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission.
- risk 0.59cvss 9.1epss 0.01
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted.
- risk 0.59cvss 9.1epss 0.01
There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to arbitrary file created.
- risk 0.59cvss 9.1epss 0.01
There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory overflow and information leakage.
- risk 0.59cvss 9.1epss 0.01
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.
Page 4 of 48