Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2016-09-07 CVE-2016-6180 Improper Access Control vulnerability in Huawei Honor 4C Firmware
The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6181, CVE-2016-6182, CVE-2016-6183, and CVE-2016-6184.
local
high complexity
huawei CWE-284
7.0
2016-08-02 CVE-2016-6193 Unspecified vulnerability in Huawei P8 Smartphone Firmware Gracl00C92B350
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6192.
local
low complexity
huawei
7.8
2016-08-02 CVE-2016-6192 Permissions, Privileges, and Access Controls vulnerability in Huawei P8 Smartphone Firmware Gracl00C92B350
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6193.
local
low complexity
huawei CWE-264
7.3
2016-08-02 CVE-2016-6178 Improper Input Validation vulnerability in Huawei products
Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.
network
low complexity
huawei CWE-20
critical
9.8
2016-07-13 CVE-2016-5821 Permissions, Privileges, and Access Controls vulnerability in Huawei Hisuite
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.
local
low complexity
huawei CWE-264
7.8
2016-07-12 CVE-2016-5850 Cross-site Scripting vulnerability in Huawei Public Cloud Solution 1.0.0
Cross-site scripting (XSS) vulnerability in the volume backup service module in Huawei Public Cloud Solution before 1.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
huawei CWE-79
5.4
2016-06-30 CVE-2016-5368 Resource Management Errors vulnerability in Huawei Ar3200 Firmware V200R005C20/V200R005C32/V200R007C00
Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted Multiprotocol Label Switching (MPLS) packets.
network
low complexity
huawei CWE-399
7.5
2016-06-30 CVE-2016-5232 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 8 Firmware NXT
Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (system crash) via a crafted app.
local
low complexity
huawei CWE-119
5.5
2016-06-30 CVE-2016-5231 Permissions, Privileges, and Access Controls vulnerability in Huawei Mate 8 Firmware NXT
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted app.
local
low complexity
huawei CWE-264
7.8
2016-06-30 CVE-2016-5230 Permissions, Privileges, and Access Controls vulnerability in Huawei Mate 8 Firmware NXT
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module functions via a crafted app.
network
low complexity
huawei CWE-264
8.8