Huawei Technologies Co Ltd Mate 9 Pro vulnerabilities

10 known vulnerabilities affecting huawei_technologies_co_ltd/mate_9_pro.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2017-17175MEDIUMCVSS 6.5vThe versions before LON-AL00B 8.0.0.354(C00)2018-07-02
CVE-2017-17175 [MEDIUM] CWE-20 CVE-2017-17175: Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) vulnerability. An unauthenticated attacker may set up a pseudo base station, and send special malware text message to the phone, causing the mobile phone to fail to make calls and send and receive text m
cvelistv5nvd
CVE-2017-17173HIGHCVSS 7.8vThe versions before LON-AL00B 8.0.0.356(C00)2018-06-14
CVE-2017-17173 [HIGH] CWE-20 CVE-2017-17173: Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the ve Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to driver to release special kernel memory resource. Suc
cvelistv5nvd
CVE-2017-17320HIGHCVSS 7.8vLON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B1882018-03-20
CVE-2017-17320 [HIGH] CWE-415 CVE-2017-17320: Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188 Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188 have a memory double free vulnerability. The system does not manage the memory properly, that frees on the same memory address twice. An attacker tricks the user who has root privilege to install a crafted application, successful exploit could result i
cvelistv5nvd
CVE-2017-17324HIGHCVSS 7.8vLON-AL00BC00B139DvLON-AL00BC00B2292018-03-09
CVE-2017-17324 [HIGH] CWE-190 CVE-2017-17324: Huawei Mate 9 Pro smartphones with software LON-AL00BC00B139D; LON-AL00BC00B229 have an integer over Huawei Mate 9 Pro smartphones with software LON-AL00BC00B139D; LON-AL00BC00B229 have an integer overflow vulnerability. The camera driver does not validate the external input parameters and causes an integer overflow, which in the after processing results in a buffer overflow. An attacker tricks the user to install a crafted application, successful ex
cvelistv5nvd
CVE-2017-17225HIGHCVSS 8.8vThe versions before LON-AL00B 8.0.0.340a(C00)2018-03-09
CVE-2017-17225 [HIGH] CWE-119 CVE-2017-17225: The Near Field Communication (NFC) module in Huawei Mate 9 Pro mobile phones with the versions befor The Near Field Communication (NFC) module in Huawei Mate 9 Pro mobile phones with the versions before LON-AL00B 8.0.0.340a(C00) has a buffer overflow vulnerability due to the lack of input validation. An attacker may use an NFC card reader or another device to inject malicious data into a target mobile phone. Successful exploit could lead to system re
cvelistv5nvd
CVE-2017-17279MEDIUMCVSS 5.5vThe versions before LON-AL00B 8.0.0.343(C00)2018-03-09
CVE-2017-17279 [MEDIUM] CVE-2017-17279: The soundtrigger module in Huawei Mate 9 Pro smart phones with software of the versions before LON-A The soundtrigger module in Huawei Mate 9 Pro smart phones with software of the versions before LON-AL00B 8.0.0.343(C00) has an authentication bypass vulnerability due to the improper design of the module. An attacker tricks a user into installing a malicious application, and the application can exploit the vulnerability and make attacker bypass the authenti
cvelistv5nvd
CVE-2017-17326MEDIUMCVSS 4.6vMate 9 Pro LON-AL00BC00B139DvLON-AL00BC00B2292018-03-09
CVE-2017-17326 [MEDIUM] CVE-2017-17326: Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activatio Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient protection of activation lock. Successful exploit could allow an attacker to byp
cvelistv5nvd
CVE-2017-15347MEDIUMCVSS 5.5vVersions earlier than LON-AL00BC00B2352018-02-15
CVE-2017-15347 [MEDIUM] CWE-416 CVE-2017-15347: Huawei Mate 9 Pro mobile phones with software of versions earlier than LON-AL00BC00B235 have a use a Huawei Mate 9 Pro mobile phones with software of versions earlier than LON-AL00BC00B235 have a use after free (UAF) vulnerability. An attacker tricks a user into installing a malicious application, and the application can riggers access memory after free it. A local attacker may exploit this vulnerability to cause the mobile phone to crash.
cvelistv5nvd
CVE-2017-15311HIGHCVSS 8.8vbefore LON-AL00B 8.0.0.334(C00),2017-12-22
CVE-2017-15311 [HIGH] CWE-119 CVE-2017-15311: The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software b The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due to the lack of parameter validation. An attacker could send malicious packe
cvelistv5nvd
CVE-2017-15316HIGHCVSS 7.8vbefore LON-AL00B 8.0.0.334(C00)2017-12-22
CVE-2017-15316 [HIGH] CWE-415 CVE-2017-15316: The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which triggers double free and ca
cvelistv5nvd