Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-2719 Command Injection vulnerability in Huawei Fusionsphere Openstack V100R006C00/V100R006C10Rc2
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port.
low complexity
huawei CWE-77
8.8
2017-11-22 CVE-2017-2718 Command Injection vulnerability in Huawei Fusionsphere Openstack V100R006C00/V100R006C10
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port.
low complexity
huawei CWE-77
8.8
2017-11-22 CVE-2017-2717 Integer Overflow or Wraparound vulnerability in Huawei Honor 8 PRO Firmware Dukel09C10B120/Dukel09C432B120/Dukel09C636B120
honor 8 Pro with software Duke-L09C10B120 and earlier versions,Duke-L09C432B120 and earlier versions,Duke-L09C636B120 and earlier versions has an integer overflow vulnerability.
low complexity
huawei CWE-190
6.5
2017-11-22 CVE-2017-2716 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 9 Firmware
The camerafs driver in Mate 9 Versions earlier than MHA-AL00BC00B173 has buffer overflow vulnerability.
local
low complexity
huawei CWE-119
7.8
2017-11-22 CVE-2017-2715 Information Exposure vulnerability in Huawei Files 7.1.1.308/7.1.1.309
The Files APP 7.1.1.309 and earlier versions in some Huawei mobile phones has a brute-force password cracking vulnerability due to the improper design of the Safe key database.
local
low complexity
huawei CWE-200
7.8
2017-11-22 CVE-2017-2714 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Fusionsphere Openstack
The GaussDB in FusionSphere OpenStack V100R005C10SPC705 and earlier versions has a buffer overflow vulnerability.
low complexity
huawei CWE-119
8.0
2017-11-22 CVE-2017-2713 Improper Input Validation vulnerability in Huawei P9 Firmware
HUAWEI P9 smartphones with software versions earlier before EVA-L09C432B383, versions earlier before EVA-L09C636B380, versions earlier before VIE-L09C432B370, versions earlier before VIE-L29C636B370 have an insufficient input validation vulnerability.
low complexity
huawei CWE-20
5.4
2017-11-22 CVE-2017-2712 Channel and Path Errors vulnerability in Huawei S3300 Firmware V100R006C05
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check.
network
low complexity
huawei CWE-417
5.3
2017-11-22 CVE-2017-2711 Improper Input Validation vulnerability in Huawei P9 Plus Firmware
P9 Plus smartphones with software earlier than VIE-AL10C00B352 versions have an input validation vulnerability in the touchscreen Driver.
local
low complexity
huawei CWE-20
5.5
2017-11-22 CVE-2017-2710 Unspecified vulnerability in Huawei Beethoven-W09A Firmware and Crr-L09 Firmware
BTV-W09C229B002CUSTC229D005,BTV-W09C233B029, earlier than BTV-W09C100B006CUSTC100D002 versions, earlier than BTV-W09C128B003CUSTC128D002 versions, earlier than BTV-W09C199B002CUSTC199D002 versions, earlier than BTV-W09C209B005CUSTC209D001 versions, earlier than BTV-W09C331B002CUSTC331D001 versions, earlier than CRR-L09C432B390 versions, earlier than CRR-L09C605B355CUSTC605D003 versions have a Factory Reset Protection (FRP) bypass security vulnerability.
low complexity
huawei
4.6