cbcvebase.

Huawei Emui vulnerabilities

831 known vulnerabilities affecting huawei/emui.

Total CVEs
831
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH465MEDIUM199LOW19

Vulnerabilities

Page 12 of 42
CVE-2023-44113P3HIGHCVSS 7.5v13.0.02023-12-06
CVE-2023-44113 [HIGH] CWE-862 CVE-2023-44113: Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) modu Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46759P3HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-11-08
CVE-2023-46759 [HIGH] CWE-284 CVE-2023-46759: Permission control vulnerability in the call module. Successful exploitation of this vulnerability m Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48299P3HIGHCVSS 7.5v12.0.12023-02-09
CVE-2022-48299 [HIGH] CWE-306 CVE-2022-48299: The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vuln The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48300P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-02-09
CVE-2022-48300 [HIGH] CWE-306 CVE-2022-48300: The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vuln The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48360P3HIGHCVSS 7.5v12.0.0v13.0.02023-03-27
CVE-2022-48360 [HIGH] CWE-276 CVE-2022-48360: The facial recognition module has a vulnerability in file permission control. Successful exploitatio The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48297P3HIGHCVSS 7.5v12.0.12023-02-09
CVE-2022-48297 [HIGH] CWE-1284 CVE-2022-48297: The geofencing kernel code has a vulnerability of not verifying the length of the input data. Succes The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2023-31227P3HIGHCVSS 7.5v13.0.02023-05-26
CVE-2023-31227 [HIGH] CWE-306 CVE-2023-31227: The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of th The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality.
nvd
CVE-2023-44104P3HIGHCVSS 7.5v11.0.1v12.0+3 more2023-10-11
CVE-2023-44104 [HIGH] CWE-669 CVE-2023-44104: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44100P3HIGHCVSS 7.5v11.0.1v12.0+3 more2023-10-11
CVE-2023-44100 [HIGH] CWE-669 CVE-2023-44100: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41301P3HIGHCVSS 7.5v12.0.0v12.0.1+1 more2023-09-25
CVE-2023-41301 [HIGH] CWE-269 CVE-2023-41301: Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerab Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-44093P3HIGHCVSS 7.5v11.0.1v12.0+3 more2023-10-11
CVE-2023-44093 [HIGH] CWE-200 CVE-2023-44093: Vulnerability of package names' public keys not being verified in the security module.Successful exp Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41298P3HIGHCVSS 7.5v12.0.1v13.0.02023-09-25
CVE-2023-41298 [HIGH] CVE-2023-41298: Vulnerability of permission control in the window module. Successful exploitation of this vulnerabil Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2024-54097P3HIGHCVSS 7.5v12.0.0v13.0.0+1 more2024-12-12
CVE-2024-54097 [HIGH] CWE-15 CVE-2024-54097: Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability ma Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.
nvd
CVE-2022-48508P3HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-07-06
CVE-2022-48508 [HIGH] CWE-264 CVE-2022-48508: Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulne Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2022-39002P3CRITICALCVSS 9.8v11.0.02022-09-16
CVE-2022-39002 [CRITICAL] CWE-415 CVE-2022-39002: Double free vulnerability in the storage module. Successful exploitation of this vulnerability will Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.
nvd
CVE-2022-39000P3CRITICALCVSS 9.8v11.0.0v11.0.1+1 more2022-09-16
CVE-2022-39000 [CRITICAL] CVE-2022-39000: The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vul The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
nvd
CVE-2023-52111P3HIGHCVSS 7.5v13.0.02024-01-16
CVE-2023-52111 [HIGH] CWE-287 CVE-2023-52111: Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2021-46851P3CRITICALCVSS 9.8v12.0.02022-11-09
CVE-2021-46851 [CRITICAL] CWE-284 CVE-2021-46851: The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitatio The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
nvd
CVE-2023-44098P3HIGHCVSS 7.5v11.0.1v12.0.1+1 more2023-11-08
CVE-2023-44098 [HIGH] CWE-200 CVE-2023-44098: Vulnerability of missing encryption in the card management module. Successful exploitation of this v Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-40019P3CRITICALCVSS 9.1v10.1.0v10.1.1+1 more2022-09-16
CVE-2021-40019 [CRITICAL] CWE-125 CVE-2021-40019: Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vu Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds access.
nvd
Huawei Emui vulnerabilities | cvebase