Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2016-04-07 CVE-2015-8318 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate S Firmware and P8 Firmware
Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2015-8319.
local
low complexity
huawei CWE-119
7.8
2016-04-07 CVE-2015-8307 Improper Access Control vulnerability in Huawei Mate S Firmware and P8 Firmware
The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an "interface access control vulnerability," a different vulnerability than CVE-2015-8680.
local
low complexity
huawei CWE-284
7.8
2016-04-07 CVE-2015-8305 Improper Input Validation vulnerability in Huawei P7 Firmware P7L07V100R001C01B606/P7L10C900B852
Huawei Sophia-L10 smartphones with software before P7-L10C900B852 allow attackers to cause a denial of service (system panic) via a crafted application with the system or camera privilege.
local
low complexity
huawei CWE-20
5.5
2016-02-15 CVE-2016-2314 Code vulnerability in Huawei Mt882 Firmware V200R002B022Arg
GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to create a directory with a long name, and then using certain other commands.
network
low complexity
huawei CWE-17
4.9
2016-02-15 CVE-2016-2231 Data Processing Errors vulnerability in Huawei Mt882 Firmware V200R002B022
The Windows-based Host Interface Program (WHIP) service on Huawei SmartAX MT882 devices V200R002B022 Arg relies on the client to send a length field that is consistent with a buffer size, which allows remote attackers to cause a denial of service (device outage) or possibly have unspecified other impact via crafted traffic on TCP port 8701.
network
low complexity
huawei CWE-19
critical
9.8
2016-02-08 CVE-2016-2214 Cross-site Scripting vulnerability in Huawei Agile Controller-Campus V100R001C00Spc315
Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
low complexity
huawei CWE-79
6.1
2016-02-01 CVE-2015-8265 Improper Input Validation vulnerability in Huawei E5151 Firmware and E5186 Firmware
Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to spoof responses via unspecified vectors.
network
low complexity
huawei CWE-20
7.5
2016-01-15 CVE-2015-8675 Credentials Management vulnerability in Huawei S5300 Firmware V200R005C02
Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password information by reading the display.
local
low complexity
huawei CWE-255
6.2
2016-01-12 CVE-2015-8673 Credentials Management vulnerability in Huawei products
Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by leveraging an unattended workstation.
low complexity
huawei CWE-255
6.8
2016-01-12 CVE-2015-8672 Data Processing Errors vulnerability in Huawei Te60 Firmware
The presentation transmission permission management mechanism in Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 allows remote attackers to cause a denial of service (wired presentation outage) via unspecified vectors involving a wireless presentation.
network
low complexity
huawei CWE-19
5.3