Huawei Magic Ui vulnerabilities

276 known vulnerabilities affecting huawei/magic_ui.

Total CVEs
276
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL64HIGH164MEDIUM46LOW2

Vulnerabilities

Page 3 of 14
CVE-2022-31760CRITICALCVSS 9.1v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31760 [CRITICAL] CVE-2022-31760: Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
cvelistv5nvd
CVE-2022-31754HIGHCVSS 7.5v3.1.02022-06-13
CVE-2022-31754 [HIGH] CVE-2022-31754: Logical defects in code implementation in some products. Successful exploitation of this vulnerabili Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the availability of some features.
cvelistv5nvd
CVE-2022-31753HIGHCVSS 7.5v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31753 [HIGH] CWE-134 CVE-2022-31753: The voice wakeup module has a vulnerability of using externally-controlled format strings. Successfu The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of this vulnerability may affect system availability.
cvelistv5nvd
CVE-2022-31762HIGHCVSS 7.8v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31762 [HIGH] CWE-20 CVE-2022-31762: The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerabilit The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
cvelistv5nvd
CVE-2022-31761HIGHCVSS 7.5v3.1.1v4.0.02022-06-13
CVE-2022-31761 [HIGH] CVE-2022-31761: Configuration defects in the secure OS module. Successful exploitation of this vulnerability will af Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality.
cvelistv5nvd
CVE-2022-31757HIGHCVSS 7.5v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31757 [HIGH] CVE-2022-31757: The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vuln The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect data confidentiality.
cvelistv5nvd
CVE-2021-46814HIGHCVSS 7.5v3.1.0v3.1.1+1 more2022-06-13
CVE-2021-46814 [HIGH] CWE-125 CVE-2021-46814: The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.
cvelistv5nvd
CVE-2021-46813HIGHCVSS 7.5v4.0.02022-06-13
CVE-2021-46813 [HIGH] CWE-212 CVE-2021-46813: Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.
cvelistv5nvd
CVE-2022-31755MEDIUMCVSS 5.5v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31755 [MEDIUM] CWE-281 CVE-2022-31755: The communication module has a vulnerability of improper permission preservation. Successful exploit The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
cvelistv5nvd
CVE-2022-31756MEDIUMCVSS 5.5v3.1.0v3.1.1+2 more2022-06-13
CVE-2022-31756 [MEDIUM] CVE-2022-31756: The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
cvelistv5nvd
CVE-2022-31759MEDIUMCVSS 5.5v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31759 [MEDIUM] CWE-824 CVE-2022-31759: AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vul AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability.
cvelistv5nvd
CVE-2022-31758MEDIUMCVSS 4.7v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31758 [MEDIUM] CWE-362 CVE-2022-31758: The kernel module has the race condition vulnerability. Successful exploitation of this vulnerabilit The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
cvelistv5nvd
CVE-2022-31751MEDIUMCVSS 5.5v3.0.0v3.1.0+2 more2022-06-13
CVE-2022-31751 [MEDIUM] CVE-2022-31751: The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability m The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.
cvelistv5nvd
CVE-2021-46811MEDIUMCVSS 5.3v3.1.0v3.1.1+1 more2022-06-13
CVE-2021-46811 [MEDIUM] CWE-276 CVE-2021-46811: HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnera HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.
cvelistv5nvd
CVE-2022-31752MEDIUMCVSS 5.5v3.1.0v3.1.1+1 more2022-06-13
CVE-2022-31752 [MEDIUM] CWE-862 CVE-2022-31752: Missing authorization vulnerability in the system components. Successful exploitation of this vulner Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.
cvelistv5nvd
CVE-2021-46786CRITICALCVSS 9.8v3.1.0v3.1.1+1 more2022-05-13
CVE-2021-46786 [CRITICAL] CWE-119 CVE-2021-46786: The audio module has a vulnerability in verifying the parameters passed by the application space.Suc The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2022-22252HIGHCVSS 7.5v3.0.0v3.1.0+2 more2022-05-13
CVE-2022-22252 [HIGH] CWE-416 CVE-2022-22252: The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect syst The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability.
nvd
CVE-2021-46789HIGHCVSS 7.5v3.0.0v3.1.0+1 more2022-05-13
CVE-2021-46789 [HIGH] CVE-2021-46789: Configuration defects in the secure OS module. Successful exploitation of this vulnerability can aff Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.
nvd
CVE-2021-46788HIGHCVSS 7.5v3.0.0v3.1.0+2 more2022-05-13
CVE-2021-46788 [HIGH] CVE-2021-46788: Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of t Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.
cvelistv5nvd
CVE-2022-29793HIGHCVSS 7.5v3.1.0v3.1.12022-05-13
CVE-2022-29793 [HIGH] CVE-2022-29793: There is a configuration defect in the activation lock of mobile phones.Successful exploitation of t There is a configuration defect in the activation lock of mobile phones.Successful exploitation of this vulnerability may affect application availability.
nvd
Huawei Magic Ui vulnerabilities | cvebase