VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2024-58108MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58106MedApr 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2022-48254MedFeb 27, 2023
    risk 0.30cvss 4.6epss 0.00

    There is a data processing error vulnerability in Leia-B29 2.0.0.49(M03). Successful exploitation could bypass lock screen authentication.

  • CVE-2021-40006MedJan 10, 2022
    risk 0.30cvss 4.6epss 0.00

    Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2021-22398MedAug 2, 2021
    risk 0.30cvss 4.6epss 0.00

    There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations. Affected…

  • CVE-2021-22440MedJul 13, 2021
    risk 0.30cvss 4.6epss 0.00

    There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software…

  • CVE-2021-22306MedFeb 6, 2021
    risk 0.30cvss 4.6epss 0.00

    There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause out-of-bound,…

  • CVE-2020-9092MedOct 19, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 20 versions earlier than 10.1.0.163(C00E160R3P8) have a JavaScript injection vulnerability. A module does not verify a specific input. This could allow attackers to bypass filter mechanism to launch JavaScript injection. This could compromise normal service of the…

  • CVE-2020-9110MedOct 12, 2020
    risk 0.30cvss 4.6epss 0.00

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an information disclosure vulnerability. The device does not sufficiently validate the output of device in certain specific scenario, the attacker can gain information in the victim's smartphone to launch the…

  • CVE-2020-9109MedOct 12, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack,…

  • CVE-2020-9106MedOct 12, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and cause information disclosure.

  • CVE-2020-9103MedAug 17, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 20 smartphones with 9.0.0.205(C00E205R2P1) have a logic error vulnerability. In a special scenario, the system does not properly process. As a result, attackers can perform a series of operations to successfully establish P2P connections that are rejected by the peer…

  • CVE-2020-1834MedJun 18, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain software package's integrity sufficiently. Successful exploit…

  • CVE-2019-19412MedJun 8, 2020
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party…

  • CVE-2020-1809MedMay 29, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 10 smartphones with versions earlier than 10.0.0.143(C00E143R2P4) have an information disclosure vulnerability. The attacker could wake up voice assistant then do a series of crafted voice operation, successful exploit could allow the attacker read certain files…

  • CVE-2020-1798MedMay 29, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. A logic error occurs when handling NFC work, an attacker should establish a NFC connection to the target phone, and then do a series of operations on the…

  • CVE-2020-1802MedApr 10, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently validate the integrity of certain file in certain loading processes, successful exploit could allow the attacker to load a crafted file to the device through…

  • CVE-2020-1794MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2020-1793MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2020-1872MedFeb 18, 2020
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), earlier than 9.1.0.252(C432E4R1P9T8), and earlier than 9.1.0.255(C576E6R1P8T8) have a digital balance bypass vulnerability. When re-configuring the mobile…

  • CVE-2020-1882MedFeb 18, 2020
    risk 0.30cvss 4.6epss 0.00

    Huawei mobile phones Ever-L29B versions earlier than 10.0.0.180(C185E6R3P3), earlier than 10.0.0.180(C432E6R1P7), earlier than 10.0.0.180(C636E5R2P3); HUAWEI Mate 20 RS versions earlier than 10.0.0.175(C786E70R3P8); HUAWEI Mate 20 X versions earlier than 10.0.0.176(C00E70R2P8);…

  • CVE-2020-1786MedJan 9, 2020
    risk 0.30cvss 4.6epss 0.00

    HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a…

  • CVE-2019-5264MedDec 13, 2019
    risk 0.30cvss 4.6epss 0.00

    There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by…

  • CVE-2019-5309MedNov 29, 2019
    risk 0.30cvss 4.6epss 0.00

    Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without unlock the screen lock. Successful exploit could cause an…

  • CVE-2019-5231MedNov 13, 2019
    risk 0.30cvss 4.6epss 0.00

    P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to…

  • CVE-2019-5220MedJul 10, 2019
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP…

  • CVE-2019-5297MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    Emily-L29C Huawei phones versions earlier than 9.0.0.159 (C185E2R1P12T8) have a Factory Reset Protection (FRP) bypass security vulnerability. Before the FRP account is verified and activated during the reset process, the attacker can perform some special operations to bypass the…

  • CVE-2019-5283MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions earlier than Emily-AL00A 9.0.0.167 (C00E81R1P21T8). When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the…

  • CVE-2019-5217MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.150 (C00E61R1P8T8). An attacker could view the photos after a series of operations without unlocking the screen lock. Successful exploit could cause an…

  • CVE-2019-5306MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions before Emily-AL00A 9.0.0.167(C00E81R1P21T8). When re-configuring the mobile phone using the FRP function, an attacker can delete the activation lock after a series of…

  • CVE-2019-5281MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is an information leak vulnerability in some Huawei phones, versions earlier than Jackman-L21 8.2.0.155(C185R1P2). When a local attacker uses the camera of a smartphone, the attacker can exploit this vulnerability to obtain sensitive information by performing a series of…

  • CVE-2018-7988MedNov 27, 2018
    risk 0.30cvss 4.6epss 0.00

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations.…

  • CVE-2018-7926MedNov 13, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to…

  • CVE-2018-7911MedOct 23, 2018
    risk 0.30cvss 4.6epss 0.00

    Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00), 8.0.0.125(SP1C00), 8.0.0.125(SP3C00), 8.0.0.126(SP2C00), 8.0.0.126(SP5C00), 8.0.0.127(SP1C00), 8.0.0.128(SP2C00), ALP-AL00B-RSC 1.0.0.2,…

  • CVE-2018-7989MedOct 17, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Mate 10 pro smartphones with the versions before BLA-AL00B 8.1.0.326(C00) have an improper authentication vulnerability. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could directly change the lock password after a series of…

  • CVE-2018-7928MedOct 9, 2018
    risk 0.30cvss 4.6epss 0.00

    There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old…

  • CVE-2018-7991MedSep 18, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei smartphones Mate10 with versions earlier before ALP-AL00B 8.0.0.110(C00) have a Factory Reset Protection (FRP) bypass vulnerability. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to the computer and then…

  • CVE-2018-7939MedSep 12, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones G9 Lite, Honor 5A, Honor 6X, Honor 8 with the versions before VNS-L53C605B120CUSTC605D103, the versions before CAM-L03C605B143CUSTC605D008, the versions before CAM-L21C10B145, the versions before CAM-L21C185B156, the versions before CAM-L21C223B133, the…

  • CVE-2018-7990MedSep 4, 2018
    risk 0.30cvss 4.6epss 0.00

    Mate10 Pro Huawei smart phones with the versions before 8.1.0.326(C00) have a FRP bypass vulnerability. During the mobile phone reseting process, an attacker could bypass "Find My Phone" protect after a series of voice and keyboard operations. Successful exploit could allow an…

  • CVE-2018-7936MedSep 4, 2018
    risk 0.30cvss 4.6epss 0.00

    Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC…

  • CVE-2017-17158MedMay 24, 2018
    risk 0.30cvss 4.6epss 0.00

    Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the…

  • CVE-2017-17326MedMar 9, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient…

  • CVE-2017-17145MedMar 9, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Honor V9 Play smart phones with the versions before Jimmy-AL00AC00B135 have an authentication bypass vulnerability due to the improper design of a component. An attacker who get a user's smart phone can execute specific operation, and delete the fingerprint of the phone…

  • CVE-2017-8173MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlier than VKY-L29C10B151 versions,earlier than VTR-L29C10B151 versions,earlier than Vicky-AL00AC00B162 versions,earlier than…

  • CVE-2017-8171MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and…

  • CVE-2017-8161MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    EVA-L09 smartphones with software Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions have Factory Reset Protection (FRP) bypass security vulnerability. When…

  • CVE-2017-8152MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An attacker can access factory reset page without authorization by only dial with special code. The…

  • CVE-2017-2721MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B1…

  • CVE-2017-2710MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    BTV-W09C229B002CUSTC229D005,BTV-W09C233B029, earlier than BTV-W09C100B006CUSTC100D002 versions, earlier than BTV-W09C128B003CUSTC128D002 versions, earlier than BTV-W09C199B002CUSTC199D002 versions, earlier than BTV-W09C209B005CUSTC209D001 versions, earlier than…

  • CVE-2017-2708MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone'…

Page 42 of 48