VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2026-49306LowAug 17, 2026
    risk 0.21cvss 3.3epss 0.00

    UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66319LowMar 5, 2026
    risk 0.21cvss 3.3epss 0.00

    Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2025-66334LowDec 8, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66333LowDec 8, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66332LowDec 8, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66331LowDec 8, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58292LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58291LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58290LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58286LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-53176LowJul 7, 2025
    risk 0.21cvss 3.3epss 0.00

    Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

  • CVE-2020-9089LowDec 27, 2024
    risk 0.21cvss 3.3epss 0.00

    There is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. Attackers with user access can exploit this vulnerability to obtain some information. This can lead to information leak. (Vulnerability ID:…

  • CVE-2020-9250LowDec 20, 2024
    risk 0.21cvss 3.3epss 0.00

    There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID:…

  • CVE-2024-32989LowMay 14, 2024
    risk 0.21cvss 3.3epss 0.00

    Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-41310LowSep 27, 2023
    risk 0.21cvss 3.3epss 0.00

    Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background.

  • CVE-2023-31225LowMay 26, 2023
    risk 0.21cvss 3.3epss 0.00

    The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability.

  • CVE-2021-22468LowOct 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage.

  • CVE-2021-22464LowOct 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause system Soft Restart.

  • CVE-2021-22457LowOct 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause out-of-bounds write.

  • CVE-2021-22453LowOct 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.

  • CVE-2021-22365LowJun 22, 2021
    risk 0.21cvss 3.3epss 0.00

    There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A local attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of internal message, successful…

  • CVE-2021-22308LowJun 3, 2021
    risk 0.21cvss 3.3epss 0.00

    There is a Business Logic Errors vulnerability in Huawei Smartphone. The malicious apps installed on the device can keep taking screenshots in the background. This issue does not cause system errors, but may cause personal information leakage.

  • CVE-2021-22294LowMar 2, 2021
    risk 0.21cvss 3.3epss 0.00

    A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerability to issue commands repeatedly, exhausting system service resources.

  • CVE-2021-22305LowFeb 6, 2021
    risk 0.21cvss 3.3epss 0.00

    There is a buffer overflow vulnerability in Mate 30 10.1.0.126(C00E125R5P3). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause buffer overflow,…

  • CVE-2021-22304LowFeb 6, 2021
    risk 0.21cvss 3.3epss 0.00

    There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to…

  • CVE-2021-22303LowFeb 6, 2021
    risk 0.21cvss 3.3epss 0.01

    There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious operation to cause pointer double free. This may lead to module…

  • CVE-2020-9203LowJan 13, 2021
    risk 0.21cvss 3.3epss 0.00

    There is a resource management errors vulnerability in Huawei P30. Local attackers construct broadcast message for some application, causing this application to send this broadcast message and impact the customer's use experience.

  • CVE-2020-9077LowJul 27, 2020
    risk 0.21cvss 3.3epss 0.01

    HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to…

  • CVE-2020-9102LowJul 17, 2020
    risk 0.21cvss 3.3epss 0.00

    There is a information leak vulnerability in some Huawei products, and it could allow a local attacker to get information. The vulnerability is due to the improper management of the username. An attacker with the ability to access the device and cause the username information…

  • CVE-2020-1862LowMar 20, 2020
    risk 0.21cvss 3.3epss 0.00

    There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful exploit may cause some service abnormal. Affected product versions…

  • CVE-2019-5292LowNov 13, 2019
    risk 0.21cvss 3.3epss 0.00

    Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an information leak vulnerability. Due to improper function error records of some module,…

  • CVE-2019-5301LowAug 8, 2019
    risk 0.21cvss 3.3epss 0.01

    Huawei smart phones Honor V20 with the versions before 9.0.1.161(C00E161R2P2) have an information leak vulnerability. An attacker may trick a user into installing a malicious application. Due to coding error during layer information processing, attackers can exploit this…

  • CVE-2018-7938LowSep 4, 2018
    risk 0.21cvss 3.3epss 0.01

    P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the lack of permission validation. An attacker tricks a user into installing a malicious application on the smart phone, and the application can read some hardware…

  • CVE-2018-7957LowJul 31, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not verify authorization correctly, attackers can exploit an application with the authorization of phone state to obtain user location additionally.

  • CVE-2017-17330LowMar 9, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V200R008C20; V200R008C30; NGFW Module V500R001C00; V500R001C20; V500R002C00 have a memory leak vulnerability. The software does not release allocated memory…

  • CVE-2017-17329LowMar 9, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei ViewPoint 8660 V100R008C03 have a memory leak vulnerability. The software does not release allocated memory properly when parse XML Schema data. An authenticated attacker could upload a crafted XML file, successful exploit could cause the system service abnormal since run…

  • CVE-2017-17321LowMar 9, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei eNSP software with software of versions earlier than V100R002C00B510 has a buffer overflow vulnerability. Due to the improper validation of specific command line parameter, a local attacker could exploit this vulnerability to cause the software process abnormal.

  • CVE-2017-8164LowMar 5, 2018
    risk 0.21cvss 3.3epss 0.01

    Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160; EVA-L09C706B145;…

  • CVE-2017-17302LowFeb 15, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory leak vulnerability. An authenticated, local attacker may craft and load…

  • CVE-2017-17294LowFeb 15, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01,…

  • CVE-2017-17293LowFeb 15, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01,…

  • CVE-2017-17292LowFeb 15, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01,…

  • CVE-2017-17289LowFeb 15, 2018
    risk 0.21cvss 3.3epss 0.00

    Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory leak vulnerability. The software does not release…

  • CVE-2017-2701LowNov 22, 2017
    risk 0.21cvss 3.3epss 0.00

    Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of…

  • CVE-2017-2694LowNov 22, 2017
    risk 0.21cvss 3.3epss 0.01

    The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly,…

  • CVE-2016-8757LowApr 2, 2017
    risk 0.21cvss 3.3epss 0.01

    ION memory management module in Huawei P9 phones with software EVA-AL10C00B192 and earlier versions, EVA-DL10C00B192 and earlier versions, EVA-TL10C00B192 and earlier versions, EVA-CL10C00B192 and earlier versions allows attackers to obtain sensitive information from…

  • CVE-2015-2246LowApr 2, 2017
    risk 0.21cvss 3.3epss 0.00

    The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the disclosure of contact information.

  • CVE-2014-8571LowApr 2, 2017
    risk 0.21cvss 3.3epss 0.00

    Apps on Huawei Ascend P6 mobile phones with software EDGE-U00 V100R001C17B508SP01 and earlier versions before V100R001C17B508SP02; EDGE-T00 V100R001C01B508SP01 and earlier versions before V100R001C01B508SP02; EDGE-C00 V100R001C92B508SP02 and earlier versions before…

  • CVE-2017-17282LowMar 9, 2018
    risk 0.20cvss 3.1epss 0.00

    SCCP (Signalling Connection Control Part) module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 has a buffer…

  • CVE-2017-15352LowFeb 15, 2018
    risk 0.20cvss 3.1epss 0.00

    Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5500 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5600 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5800 V3, V300R003C00, V300R003C10,…