Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-8186 Improper Input Validation vulnerability in Huawei Mha-Al00A
The Bastet of some Huawei mobile phones with software of earlier than MHA-AL00BC00B231 versions has a DOS vulnerability due to the lack of parameter validation.
local
low complexity
huawei CWE-20
5.5
2017-11-22 CVE-2017-8185 Exposure of Resource to Wrong Sphere vulnerability in Huawei Me906S-158 Firmware
ME906s-158 earlier than ME906S_Installer_13.1805.10.3 versions has a privilege elevation vulnerability.
local
low complexity
huawei CWE-668
7.8
2017-11-22 CVE-2017-8184 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei MTK Platform Smart Phone Firmware Niceal00C00B155/Niceal00C00B160
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability.
local
low complexity
huawei CWE-119
5.5
2017-11-22 CVE-2017-8183 Information Exposure vulnerability in Huawei MTK Platform Smart Phone Firmware Niceal00C00B155/Niceal00C00B160
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory access vulnerability.
local
low complexity
huawei CWE-200
5.5
2017-11-22 CVE-2017-8182 Out-of-bounds Read vulnerability in Huawei MTK Platform Smart Phone Firmware Niceal00C00B155/Niceal00C00B160
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability.
local
low complexity
huawei CWE-125
6.1
2017-11-22 CVE-2017-8181 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei MTK Platform Smart Phone Firmware
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a arbitrary memory write vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter to the driver of the smart phone, causing privilege escalation.
local
low complexity
huawei CWE-119
7.8
2017-11-22 CVE-2017-8180 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei MTK Platform Smart Phone Firmware
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a buffer overflow vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter to the driver of the smart phone, causing privilege escalation.
local
low complexity
huawei CWE-119
7.8
2017-11-22 CVE-2017-8179 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei MTK Platform Smart Phone Firmware
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a buffer overflow vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter to the driver of the smart phone, causing privilege escalation.
local
low complexity
huawei CWE-119
7.8
2017-11-22 CVE-2017-8178 Cross-site Scripting vulnerability in Huawei Vicky-Al00 Firmware
Huawei Email APP Vicky-AL00 smartphones with software of earlier than VKY-AL00C00B171 versions has a stored cross-site scripting vulnerability.
network
low complexity
huawei CWE-79
5.4
2017-11-22 CVE-2017-8177 Improper Verification of Cryptographic Signature vulnerability in Huawei Hiwallet
Huawei APP HiWallet earlier than 5.0.3.100 versions do not support signature verification for APK file.
network
low complexity
huawei CWE-347
5.3