Vulnerabilities (CVE)

Filtered by vendor Huawei Subscribe
Total 1706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-46840 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 9.1 CRITICAL
The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
CVE-2022-41601 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 3.4 LOW
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
CVE-2022-37003 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 N/A 9.8 CRITICAL
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
CVE-2022-41581 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 9.1 CRITICAL
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
CVE-2022-34735 1 Huawei 2 Emui, Harmonyos 2024-02-04 7.8 HIGH 7.5 HIGH
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
CVE-2022-41600 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 3.4 LOW
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
CVE-2022-38997 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 N/A 7.5 HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-34737 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 6.4 MEDIUM 9.1 CRITICAL
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
CVE-2022-38978 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 N/A 7.5 HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-44547 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 7.5 HIGH
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.
CVE-2022-44549 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 7.5 HIGH
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
CVE-2022-41589 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 7.5 HIGH
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability.
CVE-2022-38987 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 N/A 7.5 HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-37004 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 N/A 7.5 HIGH
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.
CVE-2022-39011 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 7.5 HIGH
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.
CVE-2022-38988 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 N/A 7.5 HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-44563 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 5.9 MEDIUM
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38979 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-02-04 N/A 7.5 HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38980 1 Huawei 1 Harmonyos 2024-02-04 N/A 9.8 CRITICAL
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
CVE-2022-41592 1 Huawei 2 Emui, Harmonyos 2024-02-04 N/A 3.4 LOW
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.