VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2024-45450MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-7265MedAug 8, 2024
    risk 0.26cvss 4.0epss 0.00

    Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability

  • CVE-2024-5464MedJun 14, 2024
    risk 0.26cvss 4.0epss 0.00

    Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2015-8303MedJan 8, 2016
    risk 0.26cvss 4.0epss 0.00

    Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closing a secure file, which allows local users to obtain sensitive information by pasting the contents to another file.

  • CVE-2025-53177LowJul 7, 2025
    risk 0.25cvss 3.9epss 0.00

    Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.

  • CVE-2020-1879LowMar 20, 2020
    risk 0.25cvss 3.9epss 0.00

    There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions…

  • CVE-2019-5296LowJun 4, 2019
    risk 0.25cvss 3.9epss 0.00

    Mate20 Huawei smartphones versions earlier than HMA-AL00C00B175 have an out-of-bounds read vulnerability. An attacker with a high permission runs some specific commands on the smartphone. Due to insufficient input verification, successful exploit may cause out-of-bounds read of…

  • CVE-2018-7947LowJul 31, 2018
    risk 0.25cvss 3.9epss 0.00

    Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a malicious device. In the debug mode, the malicious software in the device may exploit the vulnerability to…

  • CVE-2017-17149LowMar 9, 2018
    risk 0.25cvss 3.9epss 0.00

    Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user's Huawei ID during lock pattern change. An attacker with root privilege who gets a user's smart phone may bypass Huawei ID verification by special…

  • CVE-2020-1824LowDec 28, 2024
    risk 0.24cvss 3.7epss 0.00

    There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of…

  • CVE-2020-1823LowDec 28, 2024
    risk 0.24cvss 3.7epss 0.00

    There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of…

  • CVE-2020-1822LowDec 28, 2024
    risk 0.24cvss 3.7epss 0.00

    There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of…

  • CVE-2020-1821LowDec 28, 2024
    risk 0.24cvss 3.7epss 0.00

    There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of…

  • CVE-2020-1820LowDec 28, 2024
    risk 0.24cvss 3.7epss 0.00

    There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of…

  • CVE-2020-1819LowDec 27, 2024
    risk 0.24cvss 3.7epss 0.00

    There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of…

  • CVE-2020-1818LowDec 27, 2024
    risk 0.24cvss 3.7epss 0.00

    There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of…

  • CVE-2023-41306LowSep 27, 2023
    risk 0.24cvss 3.7epss 0.00

    Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.

  • CVE-2021-37073LowDec 7, 2021
    risk 0.24cvss 3.7epss 0.00

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the detection result is tampered with.

  • CVE-2021-36994LowOct 28, 2021
    risk 0.24cvss 3.7epss 0.00

    There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist.

  • CVE-2019-19411LowJan 21, 2020
    risk 0.24cvss 3.7epss 0.01

    USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific encryption algorithm,…

  • CVE-2017-17317LowJul 2, 2018
    risk 0.24cvss 3.7epss 0.01

    Common Open Policy Service Protocol (COPS) module in Huawei USG6300 V100R001C10; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; Secospace USG6500 V100R001C10; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; Secospace…

  • CVE-2017-17314LowApr 30, 2018
    risk 0.24cvss 3.7epss 0.01

    Huawei DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an invalid memory access vulnerability. An unauthenticated attacker has to find…

  • CVE-2017-17325LowMar 9, 2018
    risk 0.24cvss 3.7epss 0.01

    Huawei video applications HiCinema with software of 8.0.3.308; 8.0.4.300 have a permission control vulnerability. Due to improper verification of specific interface, an attacker who is on the same network with the user can obtain some information through a man-in-the-middle…

  • CVE-2017-17141LowMar 5, 2018
    risk 0.24cvss 3.7epss 0.01

    Huawei S12700 V200R005C00; V200R006C00; V200R007C00; V200R007C01; V200R007C20; V200R008C00; V200R009C00;S1700 V200R006C10; V200R009C00;S2700 V100R006C03; V200R003C00; V200R005C00; V200R006C00; V200R006C10; V200R007C00; V200R007C00B050; V200R007C00SPC009T; V200R007C00SPC019T;…

  • CVE-2017-15353LowFeb 15, 2018
    risk 0.24cvss 3.7epss 0.01

    Huawei DP300, V500R002C00, RP200, V500R002C00, V600R006C00, RSE6500, V500R002C00, TE30, V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00, V600R006C00, TE60, V100R001C01, V100R001C10, V500R002C00, V600R006C00, TX50,…

  • CVE-2017-15339LowFeb 15, 2018
    risk 0.24cvss 3.7epss 0.01

    The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00,…

  • CVE-2017-15338LowFeb 15, 2018
    risk 0.24cvss 3.7epss 0.01

    The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00,…

  • CVE-2017-15337LowFeb 15, 2018
    risk 0.24cvss 3.7epss 0.01

    The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00,…

  • CVE-2017-15321LowDec 22, 2017
    risk 0.24cvss 3.7epss 0.01

    Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default. An attacker could intercept packets transferred by a target device. Successful exploit could cause an information leak.

  • CVE-2015-8224LowSep 20, 2017
    risk 0.24cvss 3.7epss 0.01

    Huawei P8 before GRA-CL00C92B210, before GRA-L09C432B200, before GRA-TL00C01B210, and before GRA-UL00C00B210 allows remote attackers to obtain user equipment (aka UE) measurements of signal strengths.

  • CVE-2016-5233LowJun 10, 2016
    risk 0.24cvss 3.7epss 0.01

    Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitive subscriber signal strength information via vectors…

  • CVE-2026-41974LowJun 9, 2026
    risk 0.23cvss 3.6epss 0.00

    Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-41962LowMay 15, 2026
    risk 0.23cvss 3.6epss 0.00

    Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2020-9082LowDec 27, 2024
    risk 0.23cvss 3.5epss 0.00

    There is an information disclosure vulnerability in several smartphones. The system has a logic judging error under certain scenario, the attacker should gain the permit to execute commands in ADB mode and then do a series of operation on the phone. Successful exploit could…

  • CVE-2020-9081LowDec 27, 2024
    risk 0.23cvss 3.5epss 0.00

    There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) …

  • CVE-2023-52371LowFeb 18, 2024
    risk 0.23cvss 3.5epss 0.00

    Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.

  • CVE-2020-1807LowApr 27, 2020
    risk 0.23cvss 3.5epss 0.00

    HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.188(C00E74R3P8) have an improper authorization vulnerability. The software does not properly restrict certain user's modification of certain configuration file, successful exploit could allow the attacker to bypass app…

  • CVE-2019-5252LowDec 14, 2019
    risk 0.23cvss 3.5epss 0.00

    There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by…

  • CVE-2017-17280LowMar 9, 2018
    risk 0.23cvss 3.5epss 0.00

    NFC (Near Field Communication) module in Huawei mobile phones with software LON-AL00BC00 has an information leak vulnerability. The attacker has to trick a user to do some specific operations and then craft the NFC message to exploit this vulnerability. Successful exploit will…

  • CVE-2017-2730LowNov 22, 2017
    risk 0.23cvss 3.5epss 0.00

    HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier before 5.0.0 have an information leak vulnerability. When an iPhone with these APPs installed access the Wi-Fi hotpot built by attacker, the attacker can collect…

  • CVE-2022-41603LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41602LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41601LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41600LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41598LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41597LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41595LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41594LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41593LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41592LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

Page 45 of 48