VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2016-8784MedMar 9, 2018
    risk 0.28cvss 4.3epss 0.00

    Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the values of some parameters in the packet are…

  • CVE-2017-17323MedMar 9, 2018
    risk 0.28cvss 4.3epss 0.01

    Huawei iBMC V200R002C10; V200R002C20; V200R002C30 have an improper authorization vulnerability. The software incorrectly performs an authorization check when a normal user attempts to access certain information which is supposed to be accessed only by admin user. Successful…

  • CVE-2017-17322MedMar 9, 2018
    risk 0.28cvss 4.3epss 0.01

    Huawei Honor Smart Scale Application with software of 1.1.1 has an information disclosure vulnerability. The application does not sufficiently restrict the resource which can be accessed by certain protocol. An attacker could trick the user to click a malicious link, successful…

  • CVE-2017-17281MedMar 9, 2018
    risk 0.28cvss 4.3epss 0.01

    SFTP module in Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds read vulnerability. A remote, authenticated…

  • CVE-2017-17187MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input…

  • CVE-2017-17185MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a out-of-bounds read vulnerability. Due to insufficient input…

  • CVE-2017-17184MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input…

  • CVE-2017-17183MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input…

  • CVE-2017-17182MedFeb 15, 2018
    risk 0.28cvss 4.3epss 0.01

    Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a out-of-bounds read vulnerability. Due to insufficient input…

  • CVE-2017-8168MedNov 22, 2017
    risk 0.28cvss 4.3epss 0.00

    FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability. Due to an incorrect configuration item, the information transmitted by a transmission channel is not encrypted. An attacker accessing the internal network may…

  • CVE-2017-2727MedNov 22, 2017
    risk 0.28cvss 4.3epss 0.00

    Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a privilege escalation…

  • CVE-2016-2406MedMar 20, 2017
    risk 0.28cvss 4.3epss 0.01

    The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by leveraging incorrect control of permissions on the PrintScreen button.

  • CVE-2015-8336MedApr 14, 2016
    risk 0.28cvss 4.3epss 0.01

    Huawei FusionCompute with software before V100R005C10SPC700 allows remote authenticated users to obtain sensitive "role and permission" information via unspecified vectors.

  • CVE-2026-34858MedApr 13, 2026
    risk 0.27cvss 4.1epss 0.00

    UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-34860MedApr 13, 2026
    risk 0.27cvss 4.1epss 0.00

    Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2025-54650MedAug 6, 2025
    risk 0.27cvss 4.2epss 0.00

    Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

  • CVE-2025-49599MedJun 6, 2025
    risk 0.27cvss 4.1epss 0.00

    Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V5R021C00S184 allow the Epuser account to disable ONT firewall functionality, e.g., to remove the default blocking of the SSH and TELNET TCP ports, aka…

  • CVE-2024-56441MedJan 8, 2025
    risk 0.27cvss 4.1epss 0.00

    Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-54120MedJan 8, 2025
    risk 0.27cvss 4.1epss 0.00

    Race condition vulnerability in the distributed notification module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-45448MedSep 4, 2024
    risk 0.27cvss 4.1epss 0.00

    Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52720MedMay 14, 2024
    risk 0.27cvss 4.1epss 0.00

    Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2021-40041MedJan 10, 2022
    risk 0.27cvss 4.2epss 0.00

    There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could…

  • CVE-2021-22340MedJun 29, 2021
    risk 0.27cvss 4.1epss 0.00

    There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Successful exploitation of this…

  • CVE-2021-22300MedFeb 6, 2021
    risk 0.27cvss 4.1epss 0.00

    There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other…

  • CVE-2019-5307MedJun 4, 2019
    risk 0.27cvss 4.2epss 0.00

    Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a…

  • CVE-2017-17171MedJun 1, 2018
    risk 0.27cvss 4.2epss 0.00

    Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious parameters. An attacker may trick a target user into installing a malicious APK and launch attacks using a pre-installed app with specific permissions. Successful…

  • CVE-2017-8196MedNov 22, 2017
    risk 0.27cvss 4.2epss 0.00

    FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to perform, thereby querying, modifying, and deleting certain service data and making the service…

  • CVE-2026-58561MedAug 17, 2026
    risk 0.26cvss 4.0epss 0.00

    Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58560MedAug 17, 2026
    risk 0.26cvss 4.0epss 0.00

    Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28550MedMar 5, 2026
    risk 0.26cvss 4.0epss 0.00

    Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28541MedMar 5, 2026
    risk 0.26cvss 4.0epss 0.00

    Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28540MedMar 5, 2026
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-24914MedFeb 6, 2026
    risk 0.26cvss 4.0epss 0.00

    Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66329MedDec 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58277MedOct 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54616MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-53175MedJul 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

  • CVE-2025-53174MedJul 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

  • CVE-2025-53172MedJul 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

  • CVE-2025-53171MedJul 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

  • CVE-2025-53170MedJul 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Null pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2024-58117MedJul 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

  • CVE-2024-58114MedJun 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58116MedApr 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58115MedApr 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-56446MedJan 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Vulnerability of variables not being initialized in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2022-48470MedDec 28, 2024
    risk 0.26cvss 4.0epss 0.00

    Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This vulnerability has been assigned a (CVE)ID:CVE-2022-48470

  • CVE-2024-51528MedNov 5, 2024
    risk 0.26cvss 4.0epss 0.00

    Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-51524MedNov 5, 2024
    risk 0.26cvss 4.0epss 0.00

    Permission control vulnerability in the Wi-Fi module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-45445MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.

Page 44 of 48