Skip to main content

Vendor archive

huawei CVEs

Beta · best-effort

2,333 CVEs tagged to vendor huawei219 Critical, 1,012 High, 983 Medium, 119 Low, 0 Unrated.

CVE-2017-8156

Published Nov 22, 2017

The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8153

Published Nov 22, 2017

Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a maliciou…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8152

Published Nov 22, 2017

Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8151

Published Nov 22, 2017

Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design of some components. An attack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8148

Published Nov 22, 2017

Audio driver in P9 smartphones with software The versions before EVA-AL10C00B389 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8144

Published Nov 22, 2017

Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the vers…

CVSS 5.5 · Medium

CVE-2017-8141

Published Nov 22, 2017

The Touch Panel (TP) driver in P10 Plus smart phones with software versions earlier than VKY-AL00C00B153 has a memory double free vulnerability. An attacker with the root privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8140

Published Nov 22, 2017

The soundtrigger driver in P9 Plus smart phones with software versions earlier than VIE-AL10BC00B353 has a memory double free vulnerability. An attacker tricks a user into install…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8139

Published Nov 22, 2017

HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the confi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8138

Published Nov 22, 2017

HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8137

Published Nov 22, 2017

HedEx Earlier than V200R006C00 versions has a dynamic link library (DLL) hijacking vulnerability due to calling the DDL file by accessing a relative path. An attacker could exploi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8136

Published Nov 22, 2017

HedEx Earlier than V200R006C00 versions has an arbitrary file download vulnerability. An attacker could exploit it to download arbitrary files on a target device to cause informat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8135

Published Nov 22, 2017

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8134

Published Nov 22, 2017

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8133

Published Nov 22, 2017

Huawei iManager NetEco with software V600R008C00 and V600R008C10 has a command injection vulnerability. An authenticated, remote attacker could exploit this vulnerability to send…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8132

Published Nov 22, 2017

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,001-2,025 of 2,333 CVEsPage 81 of 94