Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2022-09-16 CVE-2022-39009 Improper Authentication vulnerability in Huawei Emui and Harmonyos
The WLAN module has a vulnerability in permission verification.
network
low complexity
huawei CWE-287
critical
9.8
2022-09-16 CVE-2022-39010 Unspecified vulnerability in Huawei Emui and Harmonyos
The HwChrService module has a vulnerability in permission control.
network
low complexity
huawei
7.5
2022-08-10 CVE-2022-37001 Unspecified vulnerability in Huawei Harmonyos 2.0
The diag-router module has a vulnerability in intercepting excessive long and short instructions.
network
low complexity
huawei
7.5
2022-08-10 CVE-2022-37002 Unspecified vulnerability in Huawei Emui, Harmonyos and Magic UI
The SystemUI module has a privilege escalation vulnerability.
network
low complexity
huawei
critical
9.8
2022-08-10 CVE-2022-37003 Incorrect Default Permissions vulnerability in Huawei Emui, Harmonyos and Magic UI
The AOD module has a vulnerability in permission assignment.
network
low complexity
huawei CWE-276
critical
9.8
2022-08-10 CVE-2022-37004 Unspecified vulnerability in Huawei Emui, Harmonyos and Magic UI
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE).
network
low complexity
huawei
7.5
2022-08-10 CVE-2022-37005 Argument Injection or Modification vulnerability in Huawei Emui, Harmonyos and Magic UI
The Settings application has an argument injection vulnerability.
network
low complexity
huawei CWE-88
7.5
2022-08-10 CVE-2022-37006 Incorrect Default Permissions vulnerability in Huawei Emui and Harmonyos
Permission control vulnerability in the network module.
network
low complexity
huawei CWE-276
7.5
2022-08-10 CVE-2022-37007 Out-of-bounds Read vulnerability in Huawei Emui, Harmonyos and Magic UI
The chinadrm module has an out-of-bounds read vulnerability.
network
low complexity
huawei CWE-125
7.5
2022-08-10 CVE-2022-37008 Insufficient Verification of Data Authenticity vulnerability in Huawei Emui, Harmonyos and Magic UI
The recovery module has a vulnerability of bypassing the verification of an update package before use.
network
low complexity
huawei CWE-345
7.5