Huawei Emui vulnerabilities
831 known vulnerabilities affecting huawei/emui.
Total CVEs
831
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH465MEDIUM199LOW19
Vulnerabilities
Page 14 of 42
CVE-2023-49242P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-12-06
CVE-2023-49242 [HIGH] CVE-2023-49242: Free broadcast vulnerability in the running management module. Successful exploitation of this vulne
Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49247P3HIGHCVSS 7.5v12.0.0v13.0.02023-12-06
CVE-2023-49247 [HIGH] CWE-295 CVE-2023-49247: Permission verification vulnerability in distributed scenarios. Successful exploitation of this vuln
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46771P3HIGHCVSS 7.5v12.0.0v13.0.02023-11-08
CVE-2023-46771 [HIGH] CWE-269 CVE-2023-46771: Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48350P3HIGHCVSS 7.5v13.0.02023-03-27
CVE-2022-48350 [HIGH] CWE-862 CVE-2022-48350: The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of
The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48298P3HIGHCVSS 7.5v12.0.12023-02-09
CVE-2022-48298 [HIGH] CWE-1284 CVE-2022-48298: The geofencing kernel code does not verify the length of the input data. Successful exploitation of
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2022-48606P3HIGHCVSS 7.5v11.0.1v12.0+3 more2023-09-27
CVE-2022-48606 [HIGH] CWE-476 CVE-2022-48606: Stability-related vulnerability in the binder background management and control module. Successful e
Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52388P3HIGHCVSS 7.5v12.0.0v13.0.02024-04-08
CVE-2023-52388 [HIGH] CWE-732 CVE-2023-52388: Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulner
Permission control vulnerability in the clock module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-44561P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2022-11-09
CVE-2022-44561 [HIGH] CWE-276 CVE-2022-44561: The preset launcher module has a permission verification vulnerability. Successful exploitation of t
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
nvd
CVE-2023-52549P3HIGHCVSS 7.5v12.0.0v13.0.02024-04-08
CVE-2023-52549 [HIGH] CWE-120 CVE-2023-52549: Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of t
Vulnerability of data verification errors in the kernel module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-27897P3HIGHCVSS 7.5v12.0.0v13.0.02024-04-08
CVE-2024-27897 [HIGH] CWE-200 CVE-2024-27897: Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnera
Input verification vulnerability in the call module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52550P3HIGHCVSS 7.5v12.0.0v13.0.02024-04-08
CVE-2023-52550 [HIGH] CWE-120 CVE-2023-52550: Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of t
Vulnerability of data verification errors in the kernel module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52714P3HIGHCVSS 7.5v12.0.0v13.0.02024-04-07
CVE-2023-52714 [HIGH] CWE-657 CVE-2023-52714: Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful ex
Vulnerability of defects introduced in the design process in the hwnff module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52387P3HIGHCVSS 7.5v13.0.02024-02-18
CVE-2023-52387 [HIGH] CWE-664 CVE-2023-52387: Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may af
Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41293P3HIGHCVSS 7.5v13.0.02023-09-25
CVE-2023-41293 [HIGH] CWE-227 CVE-2023-41293: Data security classification vulnerability in the DDMP module. Successful exploitation of this vulne
Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-39383P3HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-08-13
CVE-2023-39383 [HIGH] CWE-200 CVE-2023-39383: Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploita
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
nvd
CVE-2022-48494P3HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-06-19
CVE-2022-48494 [HIGH] CWE-287 CVE-2022-48494: Vulnerability of lax app identity verification in the pre-authorization function.Successful exploita
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
nvd
CVE-2022-48496P3HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-06-19
CVE-2022-48496 [HIGH] CWE-287 CVE-2022-48496: Vulnerability of lax app identity verification in the pre-authorization function.Successful exploita
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
nvd
CVE-2023-52539P3HIGHCVSS 7.5v12.0.0v13.0.02024-04-08
CVE-2023-52539 [HIGH] CWE-285 CVE-2023-52539: Permission verification vulnerability in the Settings module. Impact: Successful exploitation of thi
Permission verification vulnerability in the Settings module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52373P3HIGHCVSS 7.5v12.0.0v13.0.02024-02-18
CVE-2023-52373 [HIGH] CWE-281 CVE-2023-52373: Vulnerability of permission verification in the content sharing pop-up module.Successful exploitatio
Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.
nvd
CVE-2025-31175P3HIGHCVSS 7.5v12.0.0v13.0.0+1 more2025-04-07
CVE-2025-31175 [HIGH] CWE-502 CVE-2025-31175: Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of thi
Deserialization mismatch vulnerability in the DSoftBus module
Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd