Vulnerabilities > Huawei > High

DATE CVE VULNERABILITY TITLE RISK
2019-11-29 CVE-2019-5225 Classic Buffer Overflow vulnerability in Huawei P30 Firmware
P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an application transports to kernel.
local
low complexity
huawei CWE-120
7.8
2019-11-29 CVE-2019-5218 Improper Authentication vulnerability in Huawei Band 2 Firmware and Band 3 Firmware
There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3.
low complexity
huawei CWE-287
8.8
2019-11-29 CVE-2019-5210 Improper Validation of Array Index vulnerability in Huawei Nova 5 Firmware and Nova 5I PRO Firmware
Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(C00E170R3P2) have an improper validation of array index vulnerability.
local
low complexity
huawei CWE-129
7.8
2019-11-13 CVE-2019-5294 Out-of-bounds Read vulnerability in Huawei products
There is an out of bound read vulnerability in some Huawei products.
network
low complexity
huawei CWE-125
7.5
2019-11-13 CVE-2019-5289 Out-of-bounds Read vulnerability in Huawei Manageone 6.5.0
Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length.
network
low complexity
huawei CWE-125
7.5
2019-11-13 CVE-2019-5288 Integer Overflow or Wraparound vulnerability in Huawei P30 Firmware
P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters.
local
low complexity
huawei CWE-190
7.8
2019-11-13 CVE-2019-5287 Integer Overflow or Wraparound vulnerability in Huawei P30 Firmware
P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters.
local
low complexity
huawei CWE-190
7.8
2019-11-13 CVE-2019-5282 Double Free vulnerability in Huawei products
Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability.
local
low complexity
huawei CWE-415
7.8
2019-11-13 CVE-2019-5233 Improper Authentication vulnerability in Huawei Taurus-Al00B Firmware 10.0.0.41(Sp2C00E41R3P2)
Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability.
network
low complexity
huawei CWE-287
8.8
2019-11-12 CVE-2019-5228 Out-of-bounds Write vulnerability in Huawei P30 Firmware
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability.
local
low complexity
huawei CWE-787
7.8