Loading HuntDB...

Vulnerabilities

CVE-2024-51512

MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Published Nov 05, 2024

CVE-2024-51511

MEDIUM

Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

Published Nov 05, 2024

CVE-2024-51510

HIGH

Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Nov 05, 2024

CVE-2024-9136

MEDIUM

Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 27, 2024

CVE-2024-47294

MEDIUM

Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.

Published Sep 27, 2024

CVE-2024-47293

MEDIUM

Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.

Published Sep 27, 2024

CVE-2024-47292

MEDIUM

Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 27, 2024

CVE-2024-47291

MEDIUM

Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.

Published Sep 27, 2024

CVE-2024-47290

MEDIUM

Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.

Published Sep 27, 2024

CVE-2024-8298

MEDIUM

Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 04, 2024

CVE-2024-45449

MEDIUM

Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 04, 2024

CVE-2024-45448

MEDIUM

Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 04, 2024

CVE-2024-45447

MEDIUM

Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 04, 2024

CVE-2024-45446

MEDIUM

Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

Published Sep 04, 2024

CVE-2024-45445

MEDIUM

Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.

Published Sep 04, 2024

CVE-2024-45444

MEDIUM

Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 04, 2024

CVE-2024-45443

MEDIUM

Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Published Sep 04, 2024

CVE-2024-45442

MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.

Published Sep 04, 2024

CVE-2024-45441

MEDIUM

Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.

Published Sep 04, 2024

CVE-2024-42039

MEDIUM

Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 04, 2024

CVE-2024-45450

MEDIUM

Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Sep 04, 2024

CVE-2024-42038

HIGH

Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

Published Aug 08, 2024

CVE-2024-42037

CRITICAL

Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Aug 08, 2024

CVE-2024-42036

LOW

Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Aug 08, 2024

CVE-2024-42035

HIGH

Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.

Published Aug 08, 2024

CVE-2024-42034

MEDIUM

LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Aug 08, 2024

CVE-2024-42033

MEDIUM

Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Published Aug 08, 2024

CVE-2024-42032

MEDIUM

Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Aug 08, 2024

CVE-2024-42031

HIGH

Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Aug 08, 2024

CVE-2024-42030

MEDIUM

Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Aug 08, 2024

CVE-2023-7265

MEDIUM

Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability

Published Aug 08, 2024

CVE-2024-39672

HIGH

Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

Published Jul 25, 2024

CVE-2024-39671

CRITICAL

Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Jul 25, 2024

CVE-2023-7271

MEDIUM

Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.

Published Jul 25, 2024

CVE-2024-39670

MEDIUM

Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.

Published Jul 25, 2024

CVE-2024-39674

MEDIUM

Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

Published Jul 25, 2024

CVE-2024-39673

MEDIUM

Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Jul 25, 2024

CVE-2024-5465

MEDIUM

Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.

Published Jun 14, 2024

CVE-2024-5464

MEDIUM

Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Jun 14, 2024

CVE-2024-36503

HIGH

Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

Published Jun 14, 2024

CVE-2024-36502

HIGH

Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.

Published Jun 14, 2024

CVE-2024-36501

MEDIUM

Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.

Published Jun 14, 2024

CVE-2024-36500

HIGH

Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Jun 14, 2024

CVE-2024-36499

MEDIUM

Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Published Jun 14, 2024

CVE-2023-52712

HIGH

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM memory, thus potentially leading code execution in SMM

Published May 28, 2024

CVE-2023-52711

HIGH

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM memory thus potentially leading code execution in SMM

Published May 28, 2024

CVE-2023-52710

HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap with the beginning SMRAM.This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.

Published May 28, 2024

CVE-2023-52548

HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leveraged by a malicious OS attacker to corrupt arbitrary SMRAM memory and, in turn, lead to code execution in SMM

Published May 28, 2024

CVE-2023-52547

HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.

Published May 28, 2024

CVE-2022-48681

HIGH

Some Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause certain functions to fail.

Published May 28, 2024