Vulnerabilidades em HUAWEI
1.400 resultadosAnálise Vexday
A Huawei apresenta um perfil de risco baixo na base do Vexday, com apenas 5 CVEs registradas e nenhuma sob exploração ativa (KEV). Não há vulnerabilidades críticas identificadas nem publicações recentes, indicando estabilidade relativa no período analisado.
CVE-2021-46839CRITICALThe HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause maliciEPSS 0.5%CVE-2022-41581CRITICALThe HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause maliciousEPSS 0.5%CVE-2022-38984HIGHThe HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability EPSS 0.5%CVE-2022-38981HIGHThe HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.EPSS 0.5%CVE-2023-41302—Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause featureEPSS 0.5%CVE-2023-52378CRITICALVulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause featureEPSS 0.5%CVE-2023-37239—Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to cEPSS 0.5%CVE-2021-46895—Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability wilEPSS 0.5%CVE-2021-37085—There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.EPSS 0.5%CVE-2023-52370CRITICALStack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file acEPSS 0.5%CVE-2023-52103CRITICALBuffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.EPSS 0.5%CVE-2022-48513—Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-EPSS 0.5%CVE-2023-0116HIGHThe reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect avaiEPSS 0.5%CVE-2022-46327CRITICALSome smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in sEPSS 0.4%CVE-2023-37242—Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite thEPSS 0.4%CVE-2021-46890—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2022-44551CRITICALThe iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integriEPSS 0.4%CVE-2021-46894—Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalatioEPSS 0.4%CVE-2021-46891—Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2026-49310HIGHPermission control vulnerability in the event notification module.
Impact: Successful exploitation of this vulnerability may affect service EPSS 0.4%