cbcvebase.

Huawei Emui vulnerabilities

831 known vulnerabilities affecting huawei/emui.

Total CVEs
831
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH465MEDIUM199LOW19

Vulnerabilities

Page 16 of 42
CVE-2021-37096P3HIGHCVSS 7.5v11.0.12021-12-07
CVE-2021-37096 [HIGH] CWE-20 CVE-2021-37096: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.
nvd
CVE-2021-36992P3HIGHCVSS 7.5v10.1.1v11.0.02021-10-28
CVE-2021-36992 [HIGH] CVE-2021-36992: There is a Public key verification vulnerability in Huawei Smartphone.Successful exploitation of thi There is a Public key verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-29792P3HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29792 [HIGH] CVE-2022-29792: The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnera The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40061P3HIGHCVSS 7.5v10.1.0v10.1.1+3 more2022-03-10
CVE-2021-40061 [HIGH] CWE-843 CVE-2021-40061: There is a vulnerability of accessing resources using an incompatible type (type confusion) in the B There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2021-22392P3HIGHCVSS 7.5v9.1.0v9.1.1+4 more2021-08-02
CVE-2021-22392 [HIGH] CWE-131 CVE-2021-22392: There is an Incorrect Calculation of Buffer Size in Huawei Smartphone.Successful exploitation of thi There is an Incorrect Calculation of Buffer Size in Huawei Smartphone.Successful exploitation of this vulnerability may cause verification bypass and directions to abnormal addresses.
nvd
CVE-2020-36600P3HIGHCVSS 7.5v10.0.0v10.1.0+2 more2022-09-16
CVE-2020-36600 [HIGH] CWE-787 CVE-2020-36600: Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this v Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2023-41309P3HIGHCVSS 7.5v12.0v12.0.1+2 more2023-09-27
CVE-2023-41309 [HIGH] CWE-269 CVE-2023-41309: Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of t Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2020-36601P3HIGHCVSS 7.5v10.1.02022-09-16
CVE-2020-36601 [HIGH] CWE-787 CVE-2020-36601: Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerabili Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.
nvd
CVE-2022-39010P3HIGHCVSS 7.5v12.0.02022-09-16
CVE-2022-39010 [HIGH] CVE-2022-39010: The HwChrService module has a vulnerability in permission control. Successful exploitation of this v The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information.
nvd
CVE-2023-46769P3HIGHCVSS 7.5v13.0.02023-11-08
CVE-2023-46769 [HIGH] CWE-416 CVE-2023-46769: Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerabili Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-41308P3HIGHCVSS 7.5v12.0v12.0.1+2 more2023-09-27
CVE-2023-41308 [HIGH] CWE-532 CVE-2023-41308: Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affe Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-0116P3HIGHCVSS 7.5v12.0v12.0.1+2 more2023-05-26
CVE-2023-0116 [HIGH] CWE-306 CVE-2023-0116: The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitati The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46852P3HIGHCVSS 7.5v12.0.02022-11-09
CVE-2021-46852 [HIGH] CWE-306 CVE-2021-46852: The memory management module has the logic bypass vulnerability. Successful exploitation of this vul The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-37241P3HIGHCVSS 7.5v13.0.02023-07-06
CVE-2023-37241 [HIGH] CWE-20 CVE-2023-37241: Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may c Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2022-48517P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-07-06
CVE-2022-48517 [HIGH] CWE-701 CVE-2022-48517: Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vu Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-44556P3HIGHCVSS 7.5v12.0.0vEMUI 12.0.02022-11-08
CVE-2022-44556 [HIGH] CWE-20 CVE-2022-44556: Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability m Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-46762P3HIGHCVSS 7.5v12.0.02023-01-06
CVE-2022-46762 [HIGH] CWE-693 CVE-2022-46762: The memory management module has a logic bypass vulnerability.Successful exploitation of this vulner The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38998P3HIGHCVSS 7.5v12.0.02022-10-14
CVE-2022-38998 [HIGH] CWE-125 CVE-2022-38998: The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Succes The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
nvd
CVE-2022-38984P3HIGHCVSS 7.5v12.0.02022-10-14
CVE-2022-38984 [HIGH] CWE-125 CVE-2022-38984: The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Succes The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
nvd
CVE-2022-38985P3HIGHCVSS 7.5v12.0.02022-10-14
CVE-2022-38985 [HIGH] CWE-20 CVE-2022-38985: The facial recognition module has a vulnerability in input validation.Successful exploitation of thi The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
Huawei Emui vulnerabilities | cvebase