Huawei Emui vulnerabilities
831 known vulnerabilities affecting huawei/emui.
Total CVEs
831
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL148HIGH465MEDIUM199LOW19
Vulnerabilities
Page 8 of 42
CVE-2021-46895P3CRITICALCVSS 9.1v12.0.02023-08-13
CVE-2021-46895 [CRITICAL] CWE-701 CVE-2021-46895: Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successfu
Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.
nvd
CVE-2023-52101P3CRITICALCVSS 9.1v11.0.1v12.0.0+1 more2024-01-16
CVE-2023-52101 [CRITICAL] CWE-200 CVE-2023-52101: Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability
Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.
nvd
CVE-2023-52538P3CRITICALCVSS 9.1v12.0.0v13.0.02024-04-08
CVE-2023-52538 [CRITICAL] CWE-347 CVE-2023-52538: Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful ex
Vulnerability of package name verification being bypassed in the HwIms module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2021-22427P3HIGHCVSS 8.1v11.0.02021-08-02
CVE-2021-22427 [HIGH] CWE-362 CVE-2021-22427: There is a Heap-based Buffer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of
There is a Heap-based Buffer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.
nvd
CVE-2021-22473P3HIGHCVSS 7.5v9.1.0v9.1.1+4 more2021-10-28
CVE-2021-22473 [HIGH] CWE-287 CVE-2021-22473: There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulner
There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-22254P3HIGHCVSS 7.5v10.0.0v10.1.0+4 more2022-04-11
CVE-2022-22254 [HIGH] CVE-2022-22254: A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of
A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-22395P3HIGHCVSS 7.5v10.1.0v10.1.1+1 more2022-02-25
CVE-2021-22395 [HIGH] CWE-94 CVE-2021-22395: There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerabilit
There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41303P3HIGHCVSS 7.5v12.0.0v12.0.1+1 more2023-09-25
CVE-2023-41303 [HIGH] CWE-20 CVE-2023-41303: Command injection vulnerability in the distributed file system module. Successful exploitation of th
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.
nvd
CVE-2023-49245P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-12-06
CVE-2023-49245 [HIGH] CVE-2023-49245: Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulner
Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49243P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-12-06
CVE-2023-49243 [HIGH] CVE-2023-49243: Vulnerability of unauthorized access to email attachments in the email module. Successful exploitati
Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49239P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-12-06
CVE-2023-49239 [HIGH] CWE-863 CVE-2023-49239: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49246P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2023-12-06
CVE-2023-49246 [HIGH] CWE-863 CVE-2023-49246: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-44549P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2022-11-09
CVE-2022-44549 [HIGH] CWE-862 CVE-2022-44549: The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnera
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
nvd
CVE-2022-44557P3HIGHCVSS 7.5v11.0.1v12.0.0+1 more2022-11-09
CVE-2022-44557 [HIGH] CWE-276 CVE-2022-44557: The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-52540P3HIGHCVSS 7.5v12.0.0v13.0.02024-04-08
CVE-2023-52540 [HIGH] CWE-287 CVE-2023-52540: Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of th
Vulnerability of improper authentication in the Iaware module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-42031P3HIGHCVSS 7.5v12.0.0v13.0.0+1 more2024-08-08
CVE-2024-42031 [HIGH] CWE-16 CVE-2024-42031: Access permission verification vulnerability in the Settings module. Impact: Successful exploitation
Access permission verification vulnerability in the Settings module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54100P3HIGHCVSS 7.5v12.0.0v13.0.0+1 more2024-12-12
CVE-2024-54100 [HIGH] CWE-20 CVE-2024-54100: Vulnerability of improper access control in the secure input module Impact: Successful exploitation
Vulnerability of improper access control in the secure input module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2024-56449P3HIGHCVSS 7.5v12.0.0v13.0.0+1 more2025-01-08
CVE-2024-56449 [HIGH] CWE-840 CVE-2024-56449: Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vul
Privilege escalation vulnerability in the Account module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-28553P3HIGHCVSS 7.5v14.0.0v14.2.0+1 more2026-04-13
CVE-2026-28553 [HIGH] CWE-275 CVE-2026-28553: Vulnerability of improper permission control in the theme setting module. Impact: Successful exploit
Vulnerability of improper permission control in the theme setting module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52377P3HIGHCVSS 7.4v12.0.0v13.0.02024-02-18
CVE-2023-52377 [HIGH] CWE-120 CVE-2023-52377: Vulnerability of input data not being verified in the cellular data module.Successful exploitation o
Vulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability may cause out-of-bounds access.
nvd