Vulnerabilities > Huawei > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-09 CVE-2021-40015 Race Condition vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vulnerability may affect kernel stability.
local
high complexity
huawei CWE-362
4.7
2022-02-09 CVE-2021-40045 Improper Verification of Cryptographic Signature vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei CWE-347
5.5
2022-01-31 CVE-2021-40033 Unspecified vulnerability in Huawei products
There is an information exposure vulnerability on several Huawei Products.
local
low complexity
huawei
5.5
2022-01-31 CVE-2021-40042 Release of Invalid Pointer or Reference vulnerability in Huawei products
There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process and service abnormal.
network
low complexity
huawei CWE-763
6.5
2022-01-10 CVE-2021-40001 Path Traversal vulnerability in Huawei Harmonyos
The CaasKit module has a path traversal vulnerability.
network
low complexity
huawei CWE-22
5.3
2022-01-10 CVE-2021-40003 Path Traversal vulnerability in Huawei Harmonyos
HwPCAssistant has a path traversal vulnerability.
network
low complexity
huawei CWE-22
5.3
2022-01-10 CVE-2021-40006 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Huawei Harmonyos 2.0
Vulnerability of design defects in the security algorithm component.
low complexity
huawei CWE-327
4.6
2022-01-10 CVE-2021-40009 Out-of-bounds Write vulnerability in Huawei Emui, Harmonyos and Magic UI
There is an Out-of-bounds write vulnerability in the AOD module in smartphones.
network
low complexity
huawei CWE-787
5.3
2022-01-10 CVE-2021-40037 Type Confusion vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones.
local
low complexity
huawei CWE-843
5.5
2022-01-10 CVE-2021-40041 Cross-site Scripting vulnerability in Huawei Ws318N-21 Firmware 10.0.2.2/10.0.2.5/10.0.2.6
There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings.
local
low complexity
huawei CWE-79
4.2