Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2019-11-13 CVE-2019-5246 Insufficient Verification of Data Authenticity vulnerability in Huawei Elle-Al00B Firmware
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability.
low complexity
huawei CWE-345
6.2
2019-11-13 CVE-2019-5233 Improper Authentication vulnerability in Huawei Taurus-Al00B Firmware 10.0.0.41(Sp2C00E41R3P2)
Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability.
network
low complexity
huawei CWE-287
8.8
2019-11-13 CVE-2019-5231 Incorrect Authorization vulnerability in Huawei P30 Firmware
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability.
low complexity
huawei CWE-863
4.6
2019-11-13 CVE-2019-5230 Improper Input Validation vulnerability in Huawei Mate RS Firmware, P20 Firmware and P20 PRO Firmware
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability.
local
low complexity
huawei CWE-20
5.5
2019-11-12 CVE-2019-5229 Insufficient Verification of Data Authenticity vulnerability in Huawei P30 Firmware
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability.
low complexity
huawei CWE-345
6.2
2019-11-12 CVE-2019-5228 Out-of-bounds Write vulnerability in Huawei P30 Firmware
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability.
local
low complexity
huawei CWE-787
7.8
2019-11-12 CVE-2019-5213 Improper Authentication vulnerability in Huawei Honor Play Firmware 9.1.0.333(C00E333R1P1T8)/Cornellal00A9.0.0.156(C00E156R1P13T8)
Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentication vulnerability.
low complexity
huawei CWE-287
2.4
2019-11-12 CVE-2017-17224 NULL Pointer Dereference vulnerability in Huawei Hg655M Firmware Harryal00C9.1.0.206(C00E205R3P1)
Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability.
low complexity
huawei CWE-476
8.8
2019-10-11 CVE-2019-2215 Use After Free vulnerability in multiple products
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
local
low complexity
google debian canonical netapp huawei CWE-416
7.8
2019-09-17 CVE-2019-14835 A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. 7.8