Vulnerabilities > Huawei > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-8146 Improper Input Validation vulnerability in Huawei P10 Firmware and P10 Plus Firmware
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability.
local
low complexity
huawei CWE-20
5.5
2017-11-22 CVE-2017-8145 Improper Input Validation vulnerability in Huawei P10 Firmware and P10 Plus Firmware
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability.
local
low complexity
huawei CWE-20
5.5
2017-11-22 CVE-2017-8144 Improper Restriction of Power Consumption vulnerability in Huawei products
Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the versions before Prague-L23C605B160,the versions before MHA-AL00C00B225,the versions before LON-AL00C00B225,the versions before VTR-AL00C00B167,the versions before VTR-TL00C01B167,the versions before VKY-AL00C00B167,the versions before VKY-TL00C01B167 have a resource exhaustion vulnerability due to configure setting.
local
low complexity
huawei CWE-920
5.5
2017-11-22 CVE-2017-8143 Improper Input Validation vulnerability in Huawei Honor 5C Firmware and P9 Lite Firmware
Wi-Fi driver of Honor 5C and P9 Lite Huawei smart phones with software versions earlier than NEM-L21C432B351 and versions earlier than VNS-L21C10B381 has a DoS vulnerability.
local
low complexity
huawei CWE-20
5.5
2017-11-22 CVE-2017-8139 Cross-site Scripting vulnerability in Huawei Hedex Lite
HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability.
network
low complexity
huawei CWE-79
6.1
2017-11-22 CVE-2017-8136 Information Exposure vulnerability in Huawei Hedex Lite
HedEx Earlier than V200R006C00 versions has an arbitrary file download vulnerability.
local
low complexity
huawei CWE-200
5.5
2017-11-22 CVE-2017-8130 Information Exposure vulnerability in Huawei UMA V200R001/V300R001
The UMA product with software V200R001 and V300R001 has an information leak vulnerability.
network
low complexity
huawei CWE-200
6.5
2017-11-22 CVE-2017-8127 Cross-site Scripting vulnerability in Huawei UMA V200R001
The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation.
network
low complexity
huawei CWE-79
6.1
2017-11-22 CVE-2017-8125 Cross-site Scripting vulnerability in Huawei UMA V200R001/V300R001
The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation.
network
low complexity
huawei CWE-79
6.1
2017-11-22 CVE-2017-8121 Information Exposure vulnerability in Huawei UMA V200R001/V300R001
The UMA product with software V200R001 and V300R001 has an information leak vulnerability.
network
low complexity
huawei CWE-200
5.3