Huawei Emui vulnerabilities

820 known vulnerabilities affecting huawei/emui.

Total CVEs
820
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH461MEDIUM193LOW18

Vulnerabilities

Page 30 of 41
CVE-2021-46787HIGHCVSS 7.5v10.1.0v10.1.1+3 more2022-05-13
CVE-2021-46787 [HIGH] CVE-2021-46787: The AMS module has a vulnerability of improper permission control.Successful exploitation of this vu The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.
nvd
CVE-2022-29796HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29796 [HIGH] CVE-2022-29796: The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Success The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
nvd
CVE-2022-29791HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29791 [HIGH] CVE-2022-29791: The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Success The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
nvd
CVE-2022-29792HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29792 [HIGH] CVE-2022-29792: The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnera The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-46788HIGHCVSS 7.5v10.0.0v10.1.0+3 more2022-05-13
CVE-2021-46788 [HIGH] CVE-2021-46788: Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of t Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.
nvd
CVE-2022-29790HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29790 [HIGH] CVE-2022-29790: The graphics acceleration service has a vulnerability in multi-thread access to the database.Success The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.
nvd
CVE-2022-29789HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29789 [HIGH] CVE-2022-29789: The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Suc The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services.
nvd
CVE-2022-29795HIGHCVSS 7.5v12.0.02022-05-13
CVE-2022-29795 [HIGH] CWE-476 CVE-2022-29795: The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
nvd
CVE-2021-46785MEDIUMCVSS 5.3v12.0.02022-05-13
CVE-2021-46785 [MEDIUM] CVE-2021-46785: The Property module has a vulnerability in permission control.This vulnerability can be exploited to The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.
nvd
CVE-2022-22258CRITICALCVSS 9.8v10.1.0v10.1.1+2 more2022-04-11
CVE-2022-22258 [CRITICAL] CVE-2022-22258: The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerabili The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.
nvd
CVE-2021-46742CRITICALCVSS 9.1v10.1.0v10.1.1+3 more2022-04-11
CVE-2021-46742 [CRITICAL] CVE-2021-46742: The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secu The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2022-22253HIGHCVSS 7.5v10.0.0v10.1.0+4 more2022-04-11
CVE-2022-22253 [HIGH] CWE-354 CVE-2022-22253: The DFX module has a vulnerability of improper validation of integrity check values.Successful explo The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability.
nvd
CVE-2022-22254HIGHCVSS 7.5v10.0.0v10.1.0+4 more2022-04-11
CVE-2022-22254 [HIGH] CVE-2022-22254: A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-22256HIGHCVSS 7.5v10.0.0v10.1.0+4 more2022-04-11
CVE-2022-22256 [HIGH] CVE-2022-22256: The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40065HIGHCVSS 7.5v11.0.0v11.0.1+1 more2022-04-11
CVE-2021-40065 [HIGH] CVE-2021-40065: The communication module has a service logic error vulnerability.Successful exploitation of this vul The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-22257HIGHCVSS 7.5v10.0.0v10.1.0+4 more2022-04-11
CVE-2022-22257 [HIGH] CWE-269 CVE-2022-22257: The customization framework has a vulnerability of improper permission control.Successful exploitati The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2022-22255HIGHCVSS 7.5v12.0.02022-04-11
CVE-2022-22255 [HIGH] CVE-2022-22255: The application framework has a common DoS vulnerability.Successful exploitation of this vulnerabili The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2021-46740HIGHCVSS 7.5v12.0.02022-04-11
CVE-2021-46740 [HIGH] CWE-287 CVE-2021-46740: The device authentication service module has a defect vulnerability introduced in the design process The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40050CRITICALCVSS 9.8v10.1.0v10.1.1+3 more2022-03-10
CVE-2021-40050 [CRITICAL] CWE-125 CVE-2021-40050: There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vul There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.
nvd
CVE-2021-40053CRITICALCVSS 9.1v10.0.0v10.1.0+2 more2022-03-10
CVE-2021-40053 [CRITICAL] CWE-276 CVE-2021-40053: There is a permission control vulnerability in the Nearby module.Successful exploitation of this vul There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
nvd