VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2021-37020CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.

  • CVE-2021-37011CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.

  • CVE-2021-37042CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2021-37041CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2021-37016CriNov 23, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.

  • CVE-2021-22436CriOct 28, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Logic Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability.

  • CVE-2021-22435CriAug 2, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Configuration Defect Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability.

  • CVE-2021-22343CriJul 1, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Configuration Defect vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service integrity and availability.

  • CVE-2021-22354CriJun 30, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Information Disclosure Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2021-22373CriJun 30, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Defects Introduced in the Design Process Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service integrity and availability.

  • CVE-2021-22380CriJun 30, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality and availability.

  • CVE-2020-9142CriJan 13, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a heap base buffer overflow vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability can cause heap overflow and memory overwriting when the system incorrectly processes the update file.

  • CVE-2020-9141CriJan 13, 2021
    risk 0.59cvss 9.1epss 0.00

    There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability can cause information disclosure and malfunctions due to insufficient verification of data authenticity.

  • CVE-2020-9139CriJan 13, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a improper input validation vulnerability in some Huawei Smartphone.Successful exploit of this vulnerability can cause memory access errors and denial of service.

  • CVE-2020-9145CriJan 13, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Out-of-bounds Write vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability may cause out-of-bounds access to the physical memory.

  • CVE-2020-9233CriAug 17, 2020
    risk 0.59cvss 9.1epss 0.01

    FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some services abnormal.

  • CVE-2020-8840CriFeb 10, 2020
    risk 0.59cvss 9.8epss 0.27

    FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

  • CVE-2015-2254CriMar 13, 2019
    risk 0.59cvss 9.1epss 0.01

    Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resulting in the deletion of directory files and compromise of system functions when loading a patch.

  • CVE-2020-0022HigFeb 13, 2020
    risk 0.58cvss 8.8epss 0.06

    In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-54627HigAug 6, 2025
    risk 0.57cvss 8.8epss 0.00

    Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-48906HigJun 6, 2025
    risk 0.57cvss 8.8epss 0.00

    Authentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-31173HigApr 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2020-9236HigDec 27, 2024
    risk 0.57cvss 8.8epss 0.00

    There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit this vulnerability to perform malicious operatation to compromise module service. (Vulnerability…

  • CVE-2024-42038HigAug 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2023-6514HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.  Successful exploitation of this vulnerability may allow attackers…

  • CVE-2021-40044HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.00

    There is a permission verification vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may cause unauthorized operations.

  • CVE-2021-40002HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-40000HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-37102HigNov 23, 2021
    risk 0.57cvss 8.8epss 0.01

    There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user…

  • CVE-2020-9242HigAug 17, 2020
    risk 0.57cvss 8.8epss 0.01

    FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command injection attack.

  • CVE-2020-9079HigAug 11, 2020
    risk 0.57cvss 8.8epss 0.00

    FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protection mechanism. An attacker has to find a way to exploit the vulnerability to conduct directed attacks against the affected product.

  • CVE-2020-9257HigJul 17, 2020
    risk 0.57cvss 8.8epss 0.01

    HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a buffer overflow vulnerability. The software access data past the end, or before the…

  • CVE-2020-1832HigMay 29, 2020
    risk 0.57cvss 8.8epss 0.00

    E6878-370 products with versions of 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP1C00) have a stack buffer overflow vulnerability. The program copies an input buffer to an output buffer without verification. An attacker in the adjacent network could send a crafted message,…

  • CVE-2020-1790HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain…

  • CVE-2020-1811HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker…

  • CVE-2019-5276HigDec 23, 2019
    risk 0.57cvss 8.8epss 0.00

    Huawei smart phones with earlier versions than ELLE-AL00B 9.1.0.222(C00E220R2P1) have a buffer overflow vulnerability. An attacker may intercept and tamper with the packet in the local area network (LAN) to exploit this vulnerability. Successful exploitation may cause the…

  • CVE-2019-5218HigNov 29, 2019
    risk 0.57cvss 8.8epss 0.00

    There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.

  • CVE-2019-5233HigNov 13, 2019
    risk 0.57cvss 8.8epss 0.01

    Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.

  • CVE-2017-17224HigNov 12, 2019
    risk 0.57cvss 8.8epss 0.00

    Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the…

  • CVE-2018-7943HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.01

    There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information…

  • CVE-2018-7951HigJun 1, 2018
    risk 0.57cvss 8.8epss 0.01

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may…

  • CVE-2018-7950HigJun 1, 2018
    risk 0.57cvss 8.8epss 0.01

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may…

  • CVE-2018-7949HigJun 1, 2018
    risk 0.57cvss 8.8epss 0.01

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables…

  • CVE-2018-7904HigMay 24, 2018
    risk 0.57cvss 8.8epss 0.01

    Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain…

  • CVE-2018-7903HigMay 24, 2018
    risk 0.57cvss 8.8epss 0.01

    Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain…

  • CVE-2018-7902HigMay 24, 2018
    risk 0.57cvss 8.8epss 0.01

    Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain…

  • CVE-2018-7941HigMay 10, 2018
    risk 0.57cvss 8.8epss 0.01

    Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause…

  • CVE-2018-7932HigApr 24, 2018
    risk 0.57cvss 8.8epss 0.00

    Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded…

  • CVE-2017-17225HigMar 9, 2018
    risk 0.57cvss 8.8epss 0.01

    The Near Field Communication (NFC) module in Huawei Mate 9 Pro mobile phones with the versions before LON-AL00B 8.0.0.340a(C00) has a buffer overflow vulnerability due to the lack of input validation. An attacker may use an NFC card reader or another device to inject malicious…

  • CVE-2017-17223HigMar 9, 2018
    risk 0.57cvss 8.8epss 0.02

    Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability. An authenticated, remote attacker can craft specific URL to the affected products. Due to insufficient verification of the URL, successful…

Page 5 of 48