Total
398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-44557 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-14 | N/A | 7.5 HIGH |
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality. | |||||
CVE-2022-44558 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-14 | N/A | 9.8 CRITICAL |
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | |||||
CVE-2022-44559 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-14 | N/A | 9.8 CRITICAL |
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | |||||
CVE-2021-46852 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 7.5 HIGH |
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | |||||
CVE-2021-46851 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 9.8 CRITICAL |
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback. | |||||
CVE-2022-44549 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 7.5 HIGH |
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality. | |||||
CVE-2022-44550 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 7.5 HIGH |
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability. | |||||
CVE-2022-44562 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 9.8 CRITICAL |
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | |||||
CVE-2022-44563 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 5.9 MEDIUM |
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality. | |||||
CVE-2022-44548 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 4.3 MEDIUM |
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing. | |||||
CVE-2022-44546 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 7.5 HIGH |
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart. | |||||
CVE-2022-44547 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-10 | N/A | 7.5 HIGH |
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability. | |||||
CVE-2021-40017 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-09 | N/A | 9.8 CRITICAL |
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access. | |||||
CVE-2022-39002 | 1 Huawei | 3 Emui, Harmonyos, Magic Ui | 2022-11-03 | N/A | 9.8 CRITICAL |
Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice. | |||||
CVE-2021-40040 | 1 Huawei | 3 Emui, Harmonyos, Magic Ui | 2022-10-27 | N/A | 7.5 HIGH |
Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality. | |||||
CVE-2021-40053 | 1 Huawei | 3 Emui, Harmonyos, Magic Ui | 2022-10-27 | 6.4 MEDIUM | 9.1 CRITICAL |
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity. | |||||
CVE-2022-37006 | 1 Huawei | 2 Emui, Harmonyos | 2022-10-27 | N/A | 7.5 HIGH |
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability. | |||||
CVE-2022-38982 | 1 Huawei | 1 Harmonyos | 2022-10-20 | N/A | 9.8 CRITICAL |
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked. | |||||
CVE-2022-38980 | 1 Huawei | 1 Harmonyos | 2022-10-20 | N/A | 9.8 CRITICAL |
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions. | |||||
CVE-2021-46840 | 1 Huawei | 2 Emui, Harmonyos | 2022-10-18 | N/A | 9.1 CRITICAL |
The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. |