Huawei Emui vulnerabilities

820 known vulnerabilities affecting huawei/emui.

Total CVEs
820
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH461MEDIUM193LOW18

Vulnerabilities

Page 17 of 41
CVE-2023-37245CRITICALCVSS 9.1v12.0.0v13.0.02023-07-06
CVE-2023-37245 [CRITICAL] CWE-120 CVE-2023-37245: Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerabi Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
cvelistv5nvd
CVE-2022-48513CRITICALCVSS 9.8v11.0.1v12.0.0+2 more2023-07-06
CVE-2022-48513 [CRITICAL] CWE-290 CVE-2022-48513: Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.
cvelistv5nvd
CVE-2022-48512CRITICALCVSS 9.8v12.0.02023-07-06
CVE-2022-48512 [CRITICAL] CWE-122 CVE-2022-48512: Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this v Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.
cvelistv5nvd
CVE-2023-34164HIGHCVSS 7.5v13.0.02023-07-06
CVE-2023-34164 [HIGH] CWE-476 CVE-2023-34164: Vulnerability of incomplete input parameter verification in the communication framework module. Succ Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2022-48507HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-07-06
CVE-2022-48507 [HIGH] CWE-294 CVE-2022-48507: Vulnerability of identity verification being bypassed in the storage module. Successful exploitation Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2023-1695HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-07-06
CVE-2023-1695 [HIGH] CWE-755 CVE-2023-1695: Vulnerability of failures to capture exceptions in the communication framework. Successful exploitat Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
cvelistv5nvd
CVE-2022-48516HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-07-06
CVE-2022-48516 [HIGH] CWE-200 CVE-2022-48516: Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Succe Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality.
cvelistv5nvd
CVE-2022-48508HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-07-06
CVE-2022-48508 [HIGH] CWE-264 CVE-2022-48508: Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulne Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
cvelistv5nvd
CVE-2023-37239HIGHCVSS 7.5v12.0.1v13.0.02023-07-06
CVE-2023-37239 [HIGH] CWE-200 CVE-2023-37239: Format string vulnerability in the distributed file system. Attackers who bypass the selinux permis Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program.
cvelistv5nvd
CVE-2023-1691HIGHCVSS 7.5v11.0.1v12.0.0+2 more2023-07-06
CVE-2023-1691 [HIGH] CWE-248 CVE-2023-1691: Vulnerability of failures to capture exceptions in the communication framework. Successful exploitat Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
cvelistv5nvd
CVE-2022-48520HIGHCVSS 7.5v12.0.0v12.0.12023-07-06
CVE-2022-48520 [HIGH] CWE-200 CVE-2022-48520: Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerabil Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
cvelistv5nvd
CVE-2022-48515HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-07-06
CVE-2022-48515 [HIGH] CWE-269 CVE-2022-48515: Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnera Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2022-48519HIGHCVSS 7.5v12.0.0v12.0.12023-07-06
CVE-2022-48519 [HIGH] CWE-200 CVE-2022-48519: Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerabil Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
cvelistv5nvd
CVE-2021-46892HIGHCVSS 7.5v12.0.02023-07-06
CVE-2021-46892 [HIGH] CWE-701 CVE-2021-46892: Encryption bypass vulnerability in Maintenance mode. Successful exploitation of this vulnerability m Encryption bypass vulnerability in Maintenance mode. Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2023-37241HIGHCVSS 7.5v13.0.02023-07-06
CVE-2023-37241 [HIGH] CWE-20 CVE-2023-37241: Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may c Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
cvelistv5nvd
CVE-2022-48517HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-07-06
CVE-2022-48517 [HIGH] CWE-701 CVE-2022-48517: Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vu Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability.
cvelistv5nvd
CVE-2023-3456MEDIUMCVSS 5.3v12.0.0v13.0.0+1 more2023-07-06
CVE-2023-3456 [MEDIUM] CWE-20 CVE-2023-3456: Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2022-48518MEDIUMCVSS 5.5v12.0.0v12.0.12023-07-06
CVE-2022-48518 [MEDIUM] CWE-701 CVE-2022-48518: Vulnerability of signature verification in the iaware system being initialized later than the time w Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
cvelistv5nvd
CVE-2023-37238MEDIUMCVSS 5.3v13.0.02023-07-06
CVE-2023-37238 [MEDIUM] CWE-275 CVE-2023-37238: Vulnerability of apps' permission to access a certain API being incompletely verified in the wireles Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module. Successful exploitation of this vulnerability may affect some wireless projection features.
cvelistv5nvd
CVE-2022-48509MEDIUMCVSS 5.9v12.0.0v12.0.12023-07-06
CVE-2022-48509 [MEDIUM] CWE-476 CVE-2022-48509: Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Sh Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally.
cvelistv5nvd