Huawei Magic Ui vulnerabilities

276 known vulnerabilities affecting huawei/magic_ui.

Total CVEs
276
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL64HIGH164MEDIUM46LOW2

Vulnerabilities

Page 2 of 14
CVE-2022-37002CRITICALCVSS 9.8v3.0.0v3.1.0+2 more2022-08-10
CVE-2022-37002 [CRITICAL] CWE-269 CVE-2022-37002: The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulner The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
cvelistv5nvd
CVE-2022-37003CRITICALCVSS 9.8v4.0.02022-08-10
CVE-2022-37003 [CRITICAL] CWE-276 CVE-2022-37003: The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnera The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
cvelistv5nvd
CVE-2022-37004HIGHCVSS 7.5v3.0.0v3.1.0+2 more2022-08-10
CVE-2022-37004 [HIGH] CVE-2022-37004: The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successf The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.
cvelistv5nvd
CVE-2022-37007HIGHCVSS 7.5v4.0.02022-08-10
CVE-2022-37007 [HIGH] CWE-125 CVE-2022-37007: The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnera The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.
cvelistv5nvd
CVE-2021-40040HIGHCVSS 7.5v3.0.0v3.1.0+2 more2022-08-10
CVE-2021-40040 [HIGH] CVE-2021-40040: Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploit Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-37008HIGHCVSS 7.5v4.0.02022-08-10
CVE-2022-37008 [HIGH] CWE-345 CVE-2022-37008: The recovery module has a vulnerability of bypassing the verification of an update package before us The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
cvelistv5nvd
CVE-2021-40030HIGHCVSS 7.5v3.1.0v3.1.1+1 more2022-08-10
CVE-2021-40030 [HIGH] CVE-2021-40030: The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affe The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality.
cvelistv5nvd
CVE-2022-37005HIGHCVSS 7.5v3.1.1v4.0.02022-08-10
CVE-2022-37005 [HIGH] CWE-88 CVE-2022-37005: The Settings application has an argument injection vulnerability. Successful exploitation of this vu The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
cvelistv5nvd
CVE-2021-40034HIGHCVSS 7.5v3.1.0v3.1.1+1 more2022-08-10
CVE-2021-40034 [HIGH] CVE-2021-40034: The video framework has the memory overwriting vulnerability caused by addition overflow. Successful The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability.
cvelistv5nvd
CVE-2022-34737CRITICALCVSS 9.1v3.1.0v3.1.1+1 more2022-07-12
CVE-2022-34737 [CRITICAL] CWE-276 CVE-2022-34737: The application security module has a vulnerability in permission assignment. Successful exploitatio The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
cvelistv5nvd
CVE-2021-46741HIGHCVSS 7.5v3.0.0v3.1.0+2 more2022-07-12
CVE-2021-46741 [HIGH] CVE-2021-46741: The basic framework and setting module have defects, which were introduced during the design. Succes The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of this vulnerability may affect system integrity.
cvelistv5nvd
CVE-2021-40012HIGHCVSS 7.5v4.0.02022-07-12
CVE-2021-40012 [HIGH] CVE-2021-40012: Vulnerability of pointers being incorrectly used during data transmission in the video framework. Su Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
cvelistv5nvd
CVE-2022-34743HIGHCVSS 7.5v3.1.0v3.1.1+1 more2022-07-12
CVE-2022-34743 [HIGH] CWE-125 CVE-2022-34743: The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
cvelistv5nvd
CVE-2022-34739HIGHCVSS 7.5v3.0.0v3.1.0+2 more2022-07-12
CVE-2022-34739 [HIGH] CVE-2022-34739: The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitati The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings.
cvelistv5nvd
CVE-2022-34742HIGHCVSS 7.5v3.1.0v3.1.1+1 more2022-07-12
CVE-2022-34742 [HIGH] CWE-125 CVE-2022-34742: The system module has a read/write vulnerability. Successful exploitation of this vulnerability may The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
cvelistv5nvd
CVE-2022-34738HIGHCVSS 7.5v3.0.0v3.1.0+2 more2022-07-12
CVE-2022-34738 [HIGH] CVE-2022-34738: The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background.
cvelistv5nvd
CVE-2021-40016MEDIUMCVSS 6.5v3.1.0v3.1.1+1 more2022-07-12
CVE-2021-40016 [MEDIUM] CVE-2021-40016: Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vu Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality.
cvelistv5nvd
CVE-2022-34740MEDIUMCVSS 6.5v4.0.02022-07-12
CVE-2022-34740 [MEDIUM] CWE-120 CVE-2022-34740: The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability ma The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
cvelistv5nvd
CVE-2021-40013MEDIUMCVSS 6.5v3.1.0v3.1.1+1 more2022-07-12
CVE-2021-40013 [MEDIUM] CVE-2021-40013: Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vu Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity.
cvelistv5nvd
CVE-2022-34741MEDIUMCVSS 6.5v4.0.02022-07-12
CVE-2022-34741 [MEDIUM] CWE-120 CVE-2022-34741: The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability ma The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
cvelistv5nvd