VYPR

Vendor CVEs

Huawei

All CVEs

2,397 total · sorted by risk
  • CVE-2023-52383MedMay 14, 2024
    risk 0.31cvss 4.7epss 0.00

    Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48615MedDec 12, 2023
    risk 0.31cvss 4.8epss 0.00

    An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.

  • CVE-2022-31758MedJun 13, 2022
    risk 0.31cvss 4.7epss 0.00

    The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40015MedFeb 9, 2022
    risk 0.31cvss 4.7epss 0.00

    There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vulnerability may affect kernel stability.

  • CVE-2017-15346MedFeb 15, 2018
    risk 0.31cvss 4.7epss 0.01

    XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00,…

  • CVE-2017-15333MedFeb 15, 2018
    risk 0.31cvss 4.7epss 0.01

    XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00,…

  • CVE-2017-8148MedNov 22, 2017
    risk 0.31cvss 4.7epss 0.01

    Audio driver in P9 smartphones with software The versions before EVA-AL10C00B389 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the race condition cause null pointer accessing during the…

  • CVE-2024-58110MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58109MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58108MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58106MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2022-48254MedFeb 27, 2023
    risk 0.30cvss 4.6epss 0.00

    There is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock screen authentication.

  • CVE-2021-40006MedJan 10, 2022
    risk 0.30cvss 4.6epss 0.00

    Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2021-22398MedAug 2, 2021
    risk 0.30cvss 4.6epss 0.00

    There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations. Affected…

  • CVE-2021-22440MedJul 13, 2021
    risk 0.30cvss 4.6epss 0.00

    There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software…

  • CVE-2021-22306MedFeb 6, 2021
    risk 0.30cvss 4.6epss 0.00

    There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause out-of-bound,…

  • CVE-2020-9092MedOct 19, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 20 versions earlier than 10.1.0.163(C00E160R3P8) have a JavaScript injection vulnerability. A module does not verify a specific input. This could allow attackers to bypass filter mechanism to launch JavaScript injection. This could compromise normal service of the…

  • CVE-2020-9110MedOct 12, 2020
    risk 0.30cvss 4.6epss 0.00

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an information disclosure vulnerability. The device does not sufficiently validate the output of device in certain specific scenario, the attacker can gain information in the victim's smartphone to launch the…

  • CVE-2020-9109MedOct 12, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack,…

  • CVE-2020-9106MedOct 12, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and cause information disclosure.

  • CVE-2020-9103MedAug 17, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 20 smartphones with 9.0.0.205(C00E205R2P1) have a logic error vulnerability. In a special scenario, the system does not properly process. As a result, attackers can perform a series of operations to successfully establish P2P connections that are rejected by the peer…

  • CVE-2020-1834MedJun 18, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain software package's integrity sufficiently. Successful exploit…

  • CVE-2019-19412MedJun 8, 2020
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party…

  • CVE-2020-1809MedMay 29, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 10 smartphones with versions earlier than 10.0.0.143(C00E143R2P4) have an information disclosure vulnerability. The attacker could wake up voice assistant then do a series of crafted voice operation, successful exploit could allow the attacker read certain files…

  • CVE-2020-1798MedMay 29, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. A logic error occurs when handling NFC work, an attacker should establish a NFC connection to the target phone, and then do a series of operations on the…

  • CVE-2020-1802MedApr 10, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently validate the integrity of certain file in certain loading processes, successful exploit could allow the attacker to load a crafted file to the device through…

  • CVE-2020-1794MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2020-1793MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2020-1872MedFeb 18, 2020
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), earlier than 9.1.0.252(C432E4R1P9T8), and earlier than 9.1.0.255(C576E6R1P8T8) have a digital balance bypass vulnerability. When re-configuring the mobile…

  • CVE-2020-1882MedFeb 18, 2020
    risk 0.30cvss 4.6epss 0.00

    Huawei mobile phones Ever-L29B versions earlier than 10.0.0.180(C185E6R3P3), earlier than 10.0.0.180(C432E6R1P7), earlier than 10.0.0.180(C636E5R2P3); HUAWEI Mate 20 RS versions earlier than 10.0.0.175(C786E70R3P8); HUAWEI Mate 20 X versions earlier than 10.0.0.176(C00E70R2P8);…

  • CVE-2020-1786MedJan 9, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a…

  • CVE-2019-5264MedDec 13, 2019
    risk 0.30cvss 4.6epss 0.00

    There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by…

  • CVE-2019-5309MedNov 29, 2019
    risk 0.30cvss 4.6epss 0.00

    Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without unlock the screen lock. Successful exploit could cause an…

  • CVE-2019-5231MedNov 13, 2019
    risk 0.30cvss 4.6epss 0.00

    P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to…

  • CVE-2019-5220MedJul 10, 2019
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP…

  • CVE-2019-5297MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    Emily-L29C Huawei phones versions earlier than 9.0.0.159 (C185E2R1P12T8) have a Factory Reset Protection (FRP) bypass security vulnerability. Before the FRP account is verified and activated during the reset process, the attacker can perform some special operations to bypass the…

  • CVE-2019-5283MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions earlier than Emily-AL00A 9.0.0.167 (C00E81R1P21T8). When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the…

  • CVE-2019-5217MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.150 (C00E61R1P8T8). An attacker could view the photos after a series of operations without unlocking the screen lock. Successful exploit could cause an…

  • CVE-2019-5306MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions before Emily-AL00A 9.0.0.167(C00E81R1P21T8). When re-configuring the mobile phone using the FRP function, an attacker can delete the activation lock after a series of…

  • CVE-2019-5281MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is an information leak vulnerability in some Huawei phones, versions earlier than Jackman-L21 8.2.0.155(C185R1P2). When a local attacker uses the camera of a smartphone, the attacker can exploit this vulnerability to obtain sensitive information by performing a series of…

  • CVE-2018-7988MedNov 27, 2018
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations.…

  • CVE-2018-7926MedNov 13, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to…

  • CVE-2018-7911MedOct 23, 2018
    risk 0.30cvss 4.6epss 0.00

    Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00), 8.0.0.125(SP1C00), 8.0.0.125(SP3C00), 8.0.0.126(SP2C00), 8.0.0.126(SP5C00), 8.0.0.127(SP1C00), 8.0.0.128(SP2C00), ALP-AL00B-RSC 1.0.0.2,…

  • CVE-2018-7989MedOct 17, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Mate 10 pro smartphones with the versions before BLA-AL00B 8.1.0.326(C00) have an improper authentication vulnerability. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could directly change the lock password after a series of…

  • CVE-2018-7928MedOct 9, 2018
    risk 0.30cvss 4.6epss 0.00

    There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old…

  • CVE-2018-7991MedSep 18, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei smartphones Mate10 with versions earlier before ALP-AL00B 8.0.0.110(C00) have a Factory Reset Protection (FRP) bypass vulnerability. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to the computer and then…

  • CVE-2018-7939MedSep 12, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones G9 Lite, Honor 5A, Honor 6X, Honor 8 with the versions before VNS-L53C605B120CUSTC605D103, the versions before CAM-L03C605B143CUSTC605D008, the versions before CAM-L21C10B145, the versions before CAM-L21C185B156, the versions before CAM-L21C223B133, the…

  • CVE-2018-7990MedSep 4, 2018
    risk 0.30cvss 4.6epss 0.00

    Mate10 Pro Huawei smart phones with the versions before 8.1.0.326(C00) have a FRP bypass vulnerability. During the mobile phone reseting process, an attacker could bypass "Find My Phone" protect after a series of voice and keyboard operations. Successful exploit could allow an…

  • CVE-2018-7936MedSep 4, 2018
    risk 0.30cvss 4.6epss 0.00

    Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC…

  • CVE-2017-17158MedMay 24, 2018
    risk 0.30cvss 4.6epss 0.00

    Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the…

Page 42 of 48