Huawei Emui vulnerabilities
820 known vulnerabilities affecting huawei/emui.
Total CVEs
820
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH461MEDIUM193LOW18
Vulnerabilities
Page 2 of 41
CVE-2025-58311HIGHCVSS 7.1v14.0.0v14.2.0+1 more2025-11-28
CVE-2025-58311 [HIGH] CWE-416 CVE-2025-58311: UAF vulnerability in the USB driver module.
Impact: Successful exploitation of this vulnerability wi
UAF vulnerability in the USB driver module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
cvelistv5nvd
CVE-2025-58302MEDIUMCVSS 5.5v12.0.0v13.0.0+3 more2025-11-28
CVE-2025-58302 [MEDIUM] CWE-264 CVE-2025-58302: Permission control vulnerability in the Settings module.
Impact: Successful exploitation of this vul
Permission control vulnerability in the Settings module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2025-58276MEDIUMCVSS 5.5v12.0.0v13.0.0+2 more2025-09-05
CVE-2025-58276 [MEDIUM] CWE-264 CVE-2025-58276: Permission verification vulnerability in the home screen module
Impact: Successful exploitation of t
Permission verification vulnerability in the home screen module
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2025-54628HIGHCVSS 7.5v14.0.0v15.0.02025-08-06
CVE-2025-54628 [HIGH] CWE-118 CVE-2025-54628: Vulnerability of incomplete verification information in the communication module.
Impact: Successful
Vulnerability of incomplete verification information in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2025-54642MEDIUMCVSS 5.5v13.0.0v14.0.02025-08-06
CVE-2025-54642 [MEDIUM] CWE-20 CVE-2025-54642: Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module.
Im
Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module.
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2025-54636MEDIUMCVSS 5.5v13.0.0v14.0.02025-08-06
CVE-2025-54636 [MEDIUM] CWE-20 CVE-2025-54636: Issue of buffer overflow caused by insufficient data verification in the kernel drop detection modul
Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module.
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2025-54646MEDIUMCVSS 4.3v12.0.0v13.0.0+1 more2025-08-06
CVE-2025-54646 [MEDIUM] CWE-130 CVE-2025-54646: Vulnerability of inadequate packet length check in the BLE module.
Impact: Successful exploitation o
Vulnerability of inadequate packet length check in the BLE module.
Impact: Successful exploitation of this vulnerability may affect performance.
cvelistv5nvd
CVE-2025-54611MEDIUMCVSS 5.5v12.0.0v13.0.0+2 more2025-08-06
CVE-2025-54611 [MEDIUM] CWE-840 CVE-2025-54611: EXTRA_REFERRER resource read vulnerability in the Gallery module.
Impact: Successful exploitation of
EXTRA_REFERRER resource read vulnerability in the Gallery module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2025-54629MEDIUMCVSS 4.7v14.0.0v15.0.02025-08-06
CVE-2025-54629 [MEDIUM] CWE-362 CVE-2025-54629: Race condition issue occurring in the physical page import process of the memory management module.
Race condition issue occurring in the physical page import process of the memory management module.
Impact: Successful exploitation of this vulnerability may affect service integrity.
cvelistv5nvd
CVE-2025-54632MEDIUMCVSS 4.6v15.0.02025-08-06
CVE-2025-54632 [MEDIUM] CWE-120 CVE-2025-54632: Vulnerability of insufficient data length verification in the HVB module.
Impact: Successful exploit
Vulnerability of insufficient data length verification in the HVB module.
Impact: Successful exploitation of this vulnerability may affect service integrity.
cvelistv5nvd
CVE-2025-54641MEDIUMCVSS 5.5v13.0.0v14.0.02025-08-06
CVE-2025-54641 [MEDIUM] CWE-20 CVE-2025-54641: Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module.
Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module.
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2025-54631MEDIUMCVSS 5.5v15.0.0v14.0.02025-08-06
CVE-2025-54631 [MEDIUM] CWE-190 CVE-2025-54631: Vulnerability of insufficient data length verification in the partition module.
Impact: Successful e
Vulnerability of insufficient data length verification in the partition module.
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2025-54644MEDIUMCVSS 5.5v13.0.0v14.0.02025-08-06
CVE-2025-54644 [MEDIUM] CWE-125 CVE-2025-54644: Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light m
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2025-54637MEDIUMCVSS 5.5v13.0.0v14.0.02025-08-06
CVE-2025-54637 [MEDIUM] CWE-125 CVE-2025-54637: Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light m
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2025-54643MEDIUMCVSS 5.5v13.0.0v14.0.02025-08-06
CVE-2025-54643 [MEDIUM] CWE-125 CVE-2025-54643: Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light m
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
cvelistv5nvd
CVE-2025-53186MEDIUMCVSS 6.2v12.0.0v13.0.0+1 more2025-07-07
CVE-2025-53186 [MEDIUM] CWE-264 CVE-2025-53186: Vulnerability that allows third-party call apps to send broadcasts without verification in the audio
Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2025-53178MEDIUMCVSS 4.8v14.0.02025-07-07
CVE-2025-53178 [MEDIUM] CWE-264 CVE-2025-53178: Permission bypass vulnerability in the calendar storage module
Impact: Successful exploitation of th
Permission bypass vulnerability in the calendar storage module
Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.
cvelistv5nvd
CVE-2025-53185MEDIUMCVSS 5.5v14.0.02025-07-07
CVE-2025-53185 [MEDIUM] CWE-416 CVE-2025-53185: Virtual address reuse issue in the memory management module, which can be exploited by non-privilege
Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory
Impact: Successful exploitation of this vulnerability may affect service integrity.
cvelistv5nvd
CVE-2025-53177LOWCVSS 3.9v14.0.02025-07-07
CVE-2025-53177 [LOW] CWE-264 CVE-2025-53177: Permission bypass vulnerability in the calendar storage module
Impact: Successful exploitation of th
Permission bypass vulnerability in the calendar storage module
Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.
cvelistv5nvd
CVE-2025-48902MEDIUMCVSS 6.6v12.0.0v13.0.0+1 more2025-06-06
CVE-2025-48902 [MEDIUM] CWE-118 CVE-2025-48902: Vulnerability of uncontrolled system resource applications in the setting module
Impact: Successful
Vulnerability of uncontrolled system resource applications in the setting module
Impact: Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd