Huawei Emui vulnerabilities
831 known vulnerabilities affecting huawei/emui.
Total CVEs
831
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH465MEDIUM199LOW19
Vulnerabilities
Page 5 of 42
CVE-2022-48605P3CRITICALCVSS 9.8v13.0.0v11.0.12023-09-25
CVE-2022-48605 [CRITICAL] CWE-20 CVE-2022-48605: Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerab
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
nvd
CVE-2023-44105P3CRITICALCVSS 9.8v11.0.1v12.0.0+2 more2023-10-11
CVE-2023-44105 [CRITICAL] CWE-269 CVE-2023-44105: Vulnerability of permissions not being strictly verified in the window management module.Successful
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2021-22448P3CRITICALCVSS 9.1v9.1.0v9.1.1+4 more2022-02-25
CVE-2021-22448 [CRITICAL] CVE-2021-22448: There is an improper verification vulnerability in smartphones. Successful exploitation of this vuln
There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files.
nvd
CVE-2021-22436P3CRITICALCVSS 9.1v10.1.1v11.0.02021-10-28
CVE-2021-22436 [CRITICAL] CVE-2021-22436: There is a Logic Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerabi
There is a Logic Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability.
nvd
CVE-2022-31760P3CRITICALCVSS 9.1v10.1.0v10.1.1+2 more2022-06-13
CVE-2022-31760 [CRITICAL] CVE-2022-31760: Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
nvd
CVE-2022-39003P3CRITICALCVSS 9.1v11.0.02022-09-16
CVE-2022-39003 [CRITICAL] CWE-120 CVE-2022-39003: Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability
Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components.
nvd
CVE-2022-41581P3CRITICALCVSS 9.1v11.0.1v12.0.02022-10-14
CVE-2022-41581 [CRITICAL] CWE-125 CVE-2022-41581: The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation o
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
nvd
CVE-2023-39398P3CRITICALCVSS 9.1v11.0.1v12.0.0+2 more2023-08-13
CVE-2023-39398 [CRITICAL] CWE-275 CVE-2023-39398: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-39399P3CRITICALCVSS 9.1v11.0.1v12.0.0+2 more2023-08-13
CVE-2023-39399 [CRITICAL] CWE-275 CVE-2023-39399: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-39403P3CRITICALCVSS 9.1v11.0.1v12.0.0+2 more2023-08-13
CVE-2023-39403 [CRITICAL] CWE-358 CVE-2023-39403: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-52106P3CRITICALCVSS 9.1v13.0.02024-01-16
CVE-2023-52106 [CRITICAL] CWE-264 CVE-2023-52106: Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Succes
Vulnerability of permission verification for APIs in the DownloadProviderMain module.
Impact: Successful exploitation of this vulnerability will affect integrity and availability.
nvd
CVE-2021-22322P3HIGHCVSS 7.5v11.0.02021-06-03
CVE-2021-22322 [HIGH] CWE-306 CVE-2021-22322: There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successf
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.
nvd
CVE-2021-37054P3HIGHCVSS 7.5v10.1.12021-12-08
CVE-2021-37054 [HIGH] CWE-287 CVE-2021-37054: There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successfu
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-22434P3CRITICALCVSS 9.8v11.0.0v10.1.1+1 more2022-02-25
CVE-2021-22434 [CRITICAL] CWE-119 CVE-2021-22434: There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of thi
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
nvd
CVE-2021-22390P3CRITICALCVSS 9.8v11.0.02021-08-02
CVE-2021-22390 [CRITICAL] CWE-416 CVE-2021-22390: There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful expl
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.
nvd
CVE-2021-37121P3CRITICALCVSS 9.8v10.0.0v10.1.02022-01-03
CVE-2021-37121 [CRITICAL] CVE-2021-37121: There is a Configuration defects in Smartphone.Successful exploitation of this vulnerability may ele
There is a Configuration defects in Smartphone.Successful exploitation of this vulnerability may elevate the MEID (IMEI) permission.
nvd
CVE-2021-46786P3CRITICALCVSS 9.8v10.1.0v10.1.1+3 more2022-05-13
CVE-2021-46786 [CRITICAL] CWE-119 CVE-2021-46786: The audio module has a vulnerability in verifying the parameters passed by the application space.Suc
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2022-48288P3HIGHCVSS 7.5v12.0.12023-02-09
CVE-2022-48288 [HIGH] CWE-306 CVE-2022-48288: The bundle management module lacks authentication and control mechanisms in some APIs. Successful ex
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48289P3HIGHCVSS 7.5v12.0.12023-02-09
CVE-2022-48289 [HIGH] CWE-306 CVE-2022-48289: The bundle management module lacks authentication and control mechanisms in some APIs. Successful ex
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40017P3CRITICALCVSS 9.8v11.0.1v12.0.02022-09-16
CVE-2021-40017 [CRITICAL] CWE-20 CVE-2021-40017: The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.
nvd