Vulnerabilities in huawei
1,367 resultsCVE-2023-52540HIGHVulnerability of improper authentication in the Iaware module.
Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.4%CVE-2022-48606—Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may afEPSS 0.4%CVE-2023-44108HIGHType confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.EPSS 0.4%CVE-2022-46310HIGHThe TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentEPSS 0.4%CVE-2022-48480HIGHInteger overflow vulnerability in some phones. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2023-44107— Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability mayEPSS 0.4%CVE-2017-17224—Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attEPSS 0.4%CVE-2023-37239—Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to cEPSS 0.4%CVE-2021-46895—Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability wilEPSS 0.4%CVE-2022-48513—Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-EPSS 0.4%CVE-2021-40002—The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious commandEPSS 0.4%CVE-2021-40000—The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious commandEPSS 0.4%CVE-2022-41596HIGHThe system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized stEPSS 0.4%CVE-2023-44116—Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may caEPSS 0.4%CVE-2021-46891—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2023-37242—Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite thEPSS 0.4%CVE-2021-46894—Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalatioEPSS 0.4%CVE-2021-46890—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2023-39386—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newEPSS 0.4%CVE-2023-39389—Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause homEPSS 0.4%