cbcvebase.

Huawei Emui vulnerabilities

831 known vulnerabilities affecting huawei/emui.

Total CVEs
831
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH465MEDIUM199LOW19

Vulnerabilities

Page 17 of 42
CVE-2022-48347P3HIGHCVSS 7.5v13.0.02023-03-27
CVE-2022-48347 [HIGH] CWE-200 CVE-2022-48347: The MediaProvider module has a vulnerability in permission verification. Successful exploitation of The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2021-46868P3HIGHCVSS 7.5v12.0.02023-01-06
CVE-2021-46868 [HIGH] CWE-125 CVE-2021-46868: The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerabil The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
nvd
CVE-2021-46867P3HIGHCVSS 7.5v12.0.02023-01-06
CVE-2021-46867 [HIGH] CWE-125 CVE-2021-46867: The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerabil The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
nvd
CVE-2022-46321P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2022-12-20
CVE-2022-46321 [HIGH] CVE-2022-46321: The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vul The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48480P3HIGHCVSS 7.5v10.1.0v10.1.1+1 more2023-05-26
CVE-2022-48480 [HIGH] CWE-190 CVE-2022-48480: Integer overflow vulnerability in some phones. Successful exploitation of this vulnerability may aff Integer overflow vulnerability in some phones. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-39390P3HIGHCVSS 7.5v13.0.02023-08-13
CVE-2023-39390 [HIGH] CWE-20 CVE-2023-39390: Vulnerability of input parameter verification in certain APIs in the window management module. Succe Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2023-39404P3HIGHCVSS 7.5v13.0.02023-08-13
CVE-2023-39404 [HIGH] CWE-20 CVE-2023-39404: Vulnerability of input parameter verification in certain APIs in the window management module. Succe Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2023-39406P3HIGHCVSS 7.5v13.0.02023-08-13
CVE-2023-39406 [HIGH] CWE-264 CVE-2023-39406: Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerabi Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
nvd
CVE-2023-1694P3HIGHCVSS 7.5v11.0.1v13.0.02023-05-20
CVE-2023-1694 [HIGH] CWE-269 CVE-2023-1694: The Settings module has the file privilege escalation vulnerability.Successful exploitation of this The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-1692P3HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-05-20
CVE-2023-1692 [HIGH] CWE-732 CVE-2023-1692: The window management module lacks permission verification.Successful exploitation of this vulnerabi The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-1693P3HIGHCVSS 7.5v11.0.1v13.0.02023-05-20
CVE-2023-1693 [HIGH] CWE-269 CVE-2023-1693: The Settings module has the file privilege escalation vulnerability.Successful exploitation of this The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48286P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-02-09
CVE-2022-48286 [HIGH] CWE-269 CVE-2022-48286: The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitat The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-31226P3HIGHCVSS 7.5v13.0.02023-05-26
CVE-2023-31226 [HIGH] CWE-863 CVE-2023-31226: The SDK for the MediaPlaybackController module has improper permission verification. Successful expl The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48287P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-02-09
CVE-2022-48287 [HIGH] CWE-693 CVE-2022-48287: The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerabilit The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2023-44114P3HIGHCVSS 7.5v13.0.02023-10-11
CVE-2023-44114 [HIGH] CWE-125 CVE-2023-44114: Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerabilit Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44103P3HIGHCVSS 7.5v11.0.1v12.0+3 more2023-10-11
CVE-2023-44103 [HIGH] CWE-20 CVE-2023-44103: Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerabili Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-30413P3HIGHCVSS 7.5v13.0.02024-04-07
CVE-2024-30413 [HIGH] CWE-732 CVE-2024-30413: Vulnerability of improper permission control in the window management module. Impact: Successful exp Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-39380P3HIGHCVSS 7.5v13.0.02023-08-13
CVE-2023-39380 [HIGH] CWE-264 CVE-2023-39380: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
nvd
CVE-2021-46893P3HIGHCVSS 7.5v12.0.02023-07-05
CVE-2021-46893 [HIGH] CWE-1284 CVE-2021-46893: Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vul Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2023-52097P3HIGHCVSS 7.5v12.0.0v13.0.02024-02-18
CVE-2023-52097 [HIGH] CWE-200 CVE-2023-52097: Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploit Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
Huawei Emui vulnerabilities | cvebase