Huawei Emui vulnerabilities
831 known vulnerabilities affecting huawei/emui.
Total CVEs
831
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH465MEDIUM199LOW19
Vulnerabilities
Page 16 of 42
CVE-2021-37096P3HIGHCVSS 7.5v11.0.12021-12-07
CVE-2021-37096 [HIGH] CWE-20 CVE-2021-37096: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.
nvd
CVE-2021-36992P3HIGHCVSS 7.5v10.1.1v11.0.02021-10-28
CVE-2021-36992 [HIGH] CVE-2021-36992: There is a Public key verification vulnerability in Huawei Smartphone.Successful exploitation of thi
There is a Public key verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-29792P3HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29792 [HIGH] CVE-2022-29792: The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnera
The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40061P3HIGHCVSS 7.5v10.1.0v10.1.1+3 more2022-03-10
CVE-2021-40061 [HIGH] CWE-843 CVE-2021-40061: There is a vulnerability of accessing resources using an incompatible type (type confusion) in the B
There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2021-22392P3HIGHCVSS 7.5v9.1.0v9.1.1+4 more2021-08-02
CVE-2021-22392 [HIGH] CWE-131 CVE-2021-22392: There is an Incorrect Calculation of Buffer Size in Huawei Smartphone.Successful exploitation of thi
There is an Incorrect Calculation of Buffer Size in Huawei Smartphone.Successful exploitation of this vulnerability may cause verification bypass and directions to abnormal addresses.
nvd
CVE-2020-36600P3HIGHCVSS 7.5v10.0.0v10.1.0+2 more2022-09-16
CVE-2020-36600 [HIGH] CWE-787 CVE-2020-36600: Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this v
Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2023-41309P3HIGHCVSS 7.5v12.0v12.0.1+2 more2023-09-27
CVE-2023-41309 [HIGH] CWE-269 CVE-2023-41309: Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of t
Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2020-36601P3HIGHCVSS 7.5v10.1.02022-09-16
CVE-2020-36601 [HIGH] CWE-787 CVE-2020-36601: Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerabili
Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.
nvd
CVE-2022-39010P3HIGHCVSS 7.5v12.0.02022-09-16
CVE-2022-39010 [HIGH] CVE-2022-39010: The HwChrService module has a vulnerability in permission control. Successful exploitation of this v
The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information.
nvd
CVE-2023-46769P3HIGHCVSS 7.5v13.0.02023-11-08
CVE-2023-46769 [HIGH] CWE-416 CVE-2023-46769: Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerabili
Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-41308P3HIGHCVSS 7.5v12.0v12.0.1+2 more2023-09-27
CVE-2023-41308 [HIGH] CWE-532 CVE-2023-41308: Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affe
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-0116P3HIGHCVSS 7.5v12.0v12.0.1+2 more2023-05-26
CVE-2023-0116 [HIGH] CWE-306 CVE-2023-0116: The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitati
The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46852P3HIGHCVSS 7.5v12.0.02022-11-09
CVE-2021-46852 [HIGH] CWE-306 CVE-2021-46852: The memory management module has the logic bypass vulnerability. Successful exploitation of this vul
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-37241P3HIGHCVSS 7.5v13.0.02023-07-06
CVE-2023-37241 [HIGH] CWE-20 CVE-2023-37241: Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may c
Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2022-48517P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-07-06
CVE-2022-48517 [HIGH] CWE-701 CVE-2022-48517: Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vu
Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-44556P3HIGHCVSS 7.5v12.0.0vEMUI 12.0.02022-11-08
CVE-2022-44556 [HIGH] CWE-20 CVE-2022-44556: Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability m
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-46762P3HIGHCVSS 7.5v12.0.02023-01-06
CVE-2022-46762 [HIGH] CWE-693 CVE-2022-46762: The memory management module has a logic bypass vulnerability.Successful exploitation of this vulner
The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38998P3HIGHCVSS 7.5v12.0.02022-10-14
CVE-2022-38998 [HIGH] CWE-125 CVE-2022-38998: The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Succes
The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
nvd
CVE-2022-38984P3HIGHCVSS 7.5v12.0.02022-10-14
CVE-2022-38984 [HIGH] CWE-125 CVE-2022-38984: The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Succes
The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
nvd
CVE-2022-38985P3HIGHCVSS 7.5v12.0.02022-10-14
CVE-2022-38985 [HIGH] CWE-20 CVE-2022-38985: The facial recognition module has a vulnerability in input validation.Successful exploitation of thi
The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.
nvd