Vulnerabilities > Huawei > Sydney Al00 Firmware

DATE CVE VULNERABILITY TITLE RISK
2020-04-27 CVE-2019-5303 Improper Input Validation vulnerability in Huawei products
There are two denial of service vulnerabilities on some Huawei smartphones.
high complexity
huawei CWE-20
5.3
2020-04-27 CVE-2019-5302 Improper Input Validation vulnerability in Huawei products
There are two denial of service vulnerabilities on some Huawei smartphones.
high complexity
huawei CWE-20
5.3
2020-03-10 CVE-2020-0069 Out-of-bounds Write vulnerability in multiple products
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions.
local
low complexity
google huawei CWE-787
7.8
2019-10-11 CVE-2019-2215 Use After Free vulnerability in multiple products
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
local
low complexity
google debian canonical netapp huawei CWE-416
7.8
2019-08-14 CVE-2019-9506 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation.
8.1