VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2025-58287HigOct 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-48903HigJun 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-46584HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-31172HigApr 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-56447HigJan 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2020-9080HigDec 27, 2024
    risk 0.51cvss 7.8epss 0.00

    There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalation. (Vulnerability ID:…

  • CVE-2024-36502HigJun 14, 2024
    risk 0.51cvss 7.9epss 0.00

    Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-36500HigJun 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52712HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM…

  • CVE-2023-52711HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM…

  • CVE-2023-52710HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap with the beginning SMRAM.This can be leveraged by a malicious OS attacker to corrupt data structures stored…

  • CVE-2023-52548HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leveraged by a malicious OS attacker to corrupt arbitrary SMRAM memory and, in turn, lead to code execution in SMM

  • CVE-2023-52547HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.

  • CVE-2023-26547HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44564HigDec 28, 2022
    risk 0.51cvss 7.8epss 0.00

    Huawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access or modify protected system resources.

  • CVE-2022-41585HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.

  • CVE-2022-41584HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.

  • CVE-2022-41576HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.

  • CVE-2022-31762HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.00

    The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2021-33658HigMar 11, 2022
    risk 0.51cvss 7.8epss 0.00

    atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.

  • CVE-2021-40043HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.00

    The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the device to be visually exploitable and successful triggering…

  • CVE-2021-39992HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2021-37109HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    There is a security protection bypass vulnerability with the modem.Successful exploitation of this vulnerability may cause memory protection failure.

  • CVE-2021-39976HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictions, an authenticated local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a…

  • CVE-2021-36999HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    There is a Buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by sending malicious images and inducing users to open the images may cause remote code execution.

  • CVE-2021-22470HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.

  • CVE-2021-22458HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.

  • CVE-2021-22451HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

  • CVE-2021-22385HigAug 10, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.

  • CVE-2021-22425HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.

  • CVE-2021-22423HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.

  • CVE-2021-22422HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

  • CVE-2021-22421HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.

  • CVE-2021-22420HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..

  • CVE-2021-22418HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

  • CVE-2021-22416HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.

  • CVE-2021-22396HigAug 2, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escalation.Affected product…

  • CVE-2021-22352HigJun 30, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a Configuration Defect Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.

  • CVE-2021-22361HigJun 22, 2021
    risk 0.51cvss 7.8epss 0.00

    There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may…

  • CVE-2021-22335HigJun 3, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a Memory Buffer Improper Operation Limit vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause exceptions in image processing.

  • CVE-2020-9147HigApr 1, 2021
    risk 0.51cvss 7.8epss 0.00

    A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read.

  • CVE-2021-22314HigMar 22, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the…

  • CVE-2021-22299HigFeb 6, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions…

  • CVE-2020-9207HigDec 29, 2020
    risk 0.51cvss 7.8epss 0.01

    There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to bypass current verification mechanism. This can compromise…

  • CVE-2020-9200HigDec 24, 2020
    risk 0.51cvss 7.8epss 0.00

    There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can…

  • CVE-2020-9247HigDec 7, 2020
    risk 0.51cvss 7.8epss 0.01

    There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious…

  • CVE-2020-9117HigDec 1, 2020
    risk 0.51cvss 7.8epss 0.00

    HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific permissions crafts malformed packet with specific parameter and sends the packet…

  • CVE-2020-9114HigDec 1, 2020
    risk 0.51cvss 7.8epss 0.00

    FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful…

  • CVE-2020-9263HigOct 19, 2020
    risk 0.51cvss 7.8epss 0.01

    HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick…

  • CVE-2020-9112HigOct 19, 2020
    risk 0.51cvss 7.8epss 0.00

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the business functions of the device. An attacker could exploit this vulnerability to access the protecting information,…

Page 8 of 48