Vulnerabilities > Huawei > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-01-12 CVE-2015-8088 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 7 Firmware and P8 Firmware
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 before MT7-CL00C92B354 and P8 phones with software GRA-TL00 before GRA-TL00C01B220SP01, GRA-CL00 before GRA-CL00C92B220, GRA-CL10 before GRA-CL10C92B220, GRA-UL00 before GRA-UL00C00B220, and GRA-UL10 before GRA-UL10C00B220 allows attackers to cause a denial of service (reboot) or execute arbitrary code via a crafted application.
network
huawei CWE-119
critical
9.3
2015-05-21 CVE-2015-3911 Improper Access Control vulnerability in Huawei E587 Mobile Wifi Firmware
Huawei E587 Mobile WiFi with firmware before 11.203.30.00.00 allows remote attackers to bypass authentication, change configurations, send messages, and cause a denial of service (device restart) via unspecified vectors.
network
low complexity
huawei CWE-284
critical
9.0
2014-12-03 CVE-2014-9134 Unspecified vulnerability in Huawei products
Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
network
low complexity
huawei
critical
10.0
2013-06-20 CVE-2013-4633 Permissions, Privileges, and Access Controls vulnerability in Huawei Seco Versatile Security Manager V200R002C00/V200R002C00Spc100/V200R002C00Spc200
Huawei Seco Versatile Security Manager (VSM) before V200R002C00SPC300 allows remote authenticated users to gain privileges via a certain change to a group configuration setting.
network
low complexity
huawei CWE-264
critical
9.0
2013-06-20 CVE-2012-6570 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Huawei products
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers to conduct heap-based buffer overflow attacks and execute arbitrary code via a crafted response.
network
low complexity
huawei CWE-119
critical
10.0
2013-06-20 CVE-2012-6569 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Huawei products
Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI.
network
huawei CWE-119
critical
9.3
2009-07-01 CVE-2009-2271 Credentials Management vulnerability in Huawei D100
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access.
network
low complexity
huawei CWE-255
critical
10.0