VYPR

Vendor CVEs

Huawei

All CVEs

2,397 total · sorted by risk
  • CVE-2026-34866MedApr 13, 2026
    risk 0.33cvss 5.1epss 0.00

    Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2026-28537MedMar 5, 2026
    risk 0.33cvss 5.1epss 0.00

    Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68966MedJan 14, 2026
    risk 0.33cvss 5.1epss 0.00

    Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-68962MedJan 14, 2026
    risk 0.33cvss 5.1epss 0.00

    Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68961MedJan 14, 2026
    risk 0.33cvss 5.1epss 0.00

    Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66322MedDec 8, 2025
    risk 0.33cvss 5.1epss 0.00

    Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66321MedDec 8, 2025
    risk 0.33cvss 5.1epss 0.00

    Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66320MedDec 8, 2025
    risk 0.33cvss 5.1epss 0.00

    Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-64311MedNov 28, 2025
    risk 0.33cvss 5.1epss 0.00

    Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-58312MedNov 28, 2025
    risk 0.33cvss 5.1epss 0.00

    Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58313MedSep 5, 2025
    risk 0.33cvss 5.1epss 0.00

    Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.

  • CVE-2024-58255MedAug 8, 2025
    risk 0.33cvss 5.0epss 0.00

    EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

  • CVE-2025-54646MedAug 6, 2025
    risk 0.33cvss 5.1epss 0.00

    Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.

  • CVE-2025-54645MedAug 6, 2025
    risk 0.33cvss 5.0epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-46593MedMay 6, 2025
    risk 0.33cvss 5.1epss 0.00

    Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-46586MedMay 6, 2025
    risk 0.33cvss 5.1epss 0.00

    Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58049MedMar 4, 2025
    risk 0.33cvss 5.0epss 0.00

    Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-58047MedMar 4, 2025
    risk 0.33cvss 5.0epss 0.00

    Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54105MedDec 12, 2024
    risk 0.33cvss 5.1epss 0.00

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-51527MedNov 5, 2024
    risk 0.33cvss 5.1epss 0.00

    Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-51519MedNov 5, 2024
    risk 0.33cvss 5.0epss 0.00

    Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-51517MedNov 5, 2024
    risk 0.33cvss 5.1epss 0.00

    Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-45449MedSep 4, 2024
    risk 0.33cvss 5.1epss 0.00

    Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-45442MedSep 4, 2024
    risk 0.33cvss 5.1epss 0.00

    Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2015-2253MedJun 8, 2017
    risk 0.33cvss 5.0epss 0.01

    The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.

  • CVE-2016-8762MedApr 2, 2017
    risk 0.33cvss 5.0epss 0.00

    The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerability, which allows…

  • CVE-2025-66330MedDec 8, 2025
    risk 0.32cvss 4.9epss 0.00

    App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-64312MedNov 28, 2025
    risk 0.32cvss 4.9epss 0.00

    Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-58304MedNov 28, 2025
    risk 0.32cvss 4.9epss 0.00

    Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22341MedJun 29, 2021
    risk 0.32cvss 4.9epss 0.01

    There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module…

  • CVE-2021-22329MedJun 29, 2021
    risk 0.32cvss 4.9epss 0.00

    There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be…

  • CVE-2021-22383MedJun 22, 2021
    risk 0.32cvss 4.9epss 0.01

    There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability. An attacker can exploit…

  • CVE-2021-22342MedJun 22, 2021
    risk 0.32cvss 4.9epss 0.01

    There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include:…

  • CVE-2021-22360MedMay 27, 2021
    risk 0.32cvss 4.9epss 0.01

    There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource…

  • CVE-2020-9205MedFeb 6, 2021
    risk 0.32cvss 4.9epss 0.01

    There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to…

  • CVE-2020-1883MedJun 5, 2020
    risk 0.32cvss 4.9epss 0.01

    Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal.

  • CVE-2019-5272MedDec 26, 2019
    risk 0.32cvss 4.9epss 0.00

    USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.

  • CVE-2017-17303MedMar 9, 2018
    risk 0.32cvss 4.9epss 0.01

    Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00B018; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800;…

  • CVE-2015-8086MedOct 3, 2016
    risk 0.32cvss 4.9epss 0.00

    Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software…

  • CVE-2015-8085MedOct 3, 2016
    risk 0.32cvss 4.9epss 0.00

    Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software…

  • CVE-2016-2314MedFeb 15, 2016
    risk 0.32cvss 4.9epss 0.01

    GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to create a directory with a long name, and then using certain other commands.

  • CVE-2026-49309MedSep 9, 2026
    risk 0.31cvss 4.8epss 0.00

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-34857MedApr 13, 2026
    risk 0.31cvss 4.7epss 0.00

    UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28551MedMar 5, 2026
    risk 0.31cvss 4.7epss 0.00

    Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-24921MedFeb 6, 2026
    risk 0.31cvss 4.8epss 0.00

    Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2025-68965MedJan 14, 2026
    risk 0.31cvss 4.7epss 0.00

    Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54651MedAug 6, 2025
    risk 0.31cvss 4.8epss 0.00

    Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-53178MedJul 7, 2025
    risk 0.31cvss 4.8epss 0.00

    Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.

  • CVE-2024-47293MedSep 27, 2024
    risk 0.31cvss 4.7epss 0.00

    Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-52384MedMay 14, 2024
    risk 0.31cvss 4.7epss 0.00

    Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

Page 41 of 48