Huawei Emui vulnerabilities
820 known vulnerabilities affecting huawei/emui.
Total CVEs
820
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH461MEDIUM193LOW18
Vulnerabilities
Page 14 of 41
CVE-2023-41304MEDIUMCVSS 5.3v13.0.02023-10-11
CVE-2023-41304 [MEDIUM] CWE-754 CVE-2023-41304: Parameter verification vulnerability in the window module.Successful exploitation of this vulnerabil
Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.
cvelistv5nvd
CVE-2023-44102MEDIUMCVSS 5.3v12.0.1v13.0.02023-10-11
CVE-2023-44102 [MEDIUM] CWE-668 CVE-2023-44102: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.
cvelistv5nvd
CVE-2023-44094MEDIUMCVSS 5.3v12.0v12.0.1+2 more2023-10-11
CVE-2023-44094 [MEDIUM] CWE-843 CVE-2023-44094: Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerab
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
cvelistv5nvd
CVE-2023-44110MEDIUMCVSS 4.3v12.0.1v13.0.02023-10-11
CVE-2023-44110 [MEDIUM] CWE-20 CVE-2023-44110: Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability
Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2023-41308HIGHCVSS 7.5v12.0v12.0.1+2 more2023-09-27
CVE-2023-41308 [HIGH] CWE-532 CVE-2023-41308: Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affe
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
cvelistv5nvd
CVE-2023-41305HIGHCVSS 7.5v11.0.1v12.0+3 more2023-09-27
CVE-2023-41305 [HIGH] CWE-326 CVE-2023-41305: Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS mess
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
cvelistv5nvd
CVE-2023-41307HIGHCVSS 7.5v12.0v13.0.0+1 more2023-09-27
CVE-2023-41307 [HIGH] CWE-787 CVE-2023-41307: Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerabili
Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2023-41309HIGHCVSS 7.5v12.0v12.0.1+2 more2023-09-27
CVE-2023-41309 [HIGH] CWE-269 CVE-2023-41309: Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of t
Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2022-48606HIGHCVSS 7.5v11.0.1v12.0+3 more2023-09-27
CVE-2022-48606 [HIGH] CWE-476 CVE-2022-48606: Stability-related vulnerability in the binder background management and control module. Successful e
Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2023-41311MEDIUMCVSS 5.3v12.0.1v13.0.02023-09-27
CVE-2023-41311 [MEDIUM] CWE-284 CVE-2023-41311: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
cvelistv5nvd
CVE-2023-41312MEDIUMCVSS 5.3v12.0.1v13.0.02023-09-27
CVE-2023-41312 [MEDIUM] CWE-269 CVE-2023-41312: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
cvelistv5nvd
CVE-2023-4565MEDIUMCVSS 5.3v11.0.1v12.0.0+2 more2023-09-27
CVE-2023-4565 [MEDIUM] CWE-732 CVE-2023-4565: Broadcast permission control vulnerability in the framework module. Successful exploitation of this
Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable.
cvelistv5nvd
CVE-2023-41306LOWCVSS 3.7v12.0v12.0.1+1 more2023-09-27
CVE-2023-41306 [LOW] CWE-362 CVE-2023-41306: Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful e
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.
cvelistv5nvd
CVE-2023-41310LOWCVSS 3.3v11.0.1v12.0+3 more2023-09-27
CVE-2023-41310 [LOW] CWE-400 CVE-2023-41310: Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerab
Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background.
cvelistv5nvd
CVE-2023-41296CRITICALCVSS 9.1v11.0.1v12.0+3 more2023-09-25
CVE-2023-41296 [CRITICAL] CWE-862 CVE-2023-41296: Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnera
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
cvelistv5nvd
CVE-2023-41297CRITICALCVSS 9.8v12.0.02023-09-25
CVE-2023-41297 [CRITICAL] CVE-2023-41297: Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exp
Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
cvelistv5nvd
CVE-2022-48605CRITICALCVSS 9.8v13.0.0v11.0.12023-09-25
CVE-2022-48605 [CRITICAL] CWE-20 CVE-2022-48605: Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerab
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
cvelistv5nvd
CVE-2023-41301HIGHCVSS 7.5v12.0.0v12.0.1+1 more2023-09-25
CVE-2023-41301 [HIGH] CWE-269 CVE-2023-41301: Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerab
Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
cvelistv5nvd
CVE-2023-39408HIGHCVSS 7.5v11.0.1v12.0+3 more2023-09-25
CVE-2023-39408 [HIGH] CWE-120 CVE-2023-39408: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
cvelistv5nvd
CVE-2023-39409HIGHCVSS 7.5v11.0.1v12.0+3 more2023-09-25
CVE-2023-39409 [HIGH] CWE-120 CVE-2023-39409: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
cvelistv5nvd