Lucene search

K

Beethoven-W09A, CRR-L09 Security Vulnerabilities

huawei
huawei

Security Advisory - Information Leakage Vulnerability in Motion Sensor

Motion sensor in some Huawei smart phones has an information leakage vulnerability. An attacker may exploit this vulnerability to obtain specific information from the motion sensor through an APP installed on the smart phone and track the user. Successful exploit may cause information leak....

3.3CVSS

6.3AI Score

0.0004EPSS

2020-03-11 12:00 AM
54
cve
cve

CVE-2020-1792

Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter....

5.5CVSS

5.6AI Score

0.001EPSS

2020-02-28 07:15 PM
88
nvd
nvd

CVE-2020-1792

Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter....

5.5CVSS

5.5AI Score

0.001EPSS

2020-02-28 07:15 PM
prion
prion

Input validation

Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter....

5.5CVSS

5.5AI Score

0.001EPSS

2020-02-28 07:15 PM
5
cvelist
cvelist

CVE-2020-1792

Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter....

5.6AI Score

0.001EPSS

2020-02-28 06:58 PM
huawei
huawei

Security Advisory - Out of Bounds Write Vulnerability in Several Smartphones

There is an out of bounds write vulnerability in several smartphones. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter when initializing certain driver program. An attacker could trick the user into installing a malicious...

5.5CVSS

5.5AI Score

0.001EPSS

2020-02-26 12:00 AM
50
openbugbounty
openbugbounty

cv30.co Cross Site Scripting vulnerability

Open Bug Bounty ID: OBB-1082023 Security Researcher sardhara_badal Helped patch 267 vulnerabilities Received 3 Coordinated Disclosure badges Received 3 recommendations , a holder of 3 badges for responsible and coordinated disclosure, found a security vulnerability affecting cv30.co website and...

0.2AI Score

2020-02-02 03:55 AM
7
openbugbounty
openbugbounty

bynorth.com Cross Site Scripting vulnerability

Open Bug Bounty ID: OBB-1078758 Security Researcher 4N_CURZE Helped patch 1496 vulnerabilities Received 7 Coordinated Disclosure badges Received 12 recommendations , a holder of 7 badges for responsible and coordinated disclosure, found a security vulnerability affecting bynorth.com website and...

0.1AI Score

2020-01-29 07:44 PM
10
openbugbounty
openbugbounty

sapia.com.pe Cross Site Scripting vulnerability

Open Bug Bounty ID: OBB-1073010 Security Researcher geeknik Helped patch 8781 vulnerabilities Received 8 Coordinated Disclosure badges Received 20 recommendations , a holder of 8 badges for responsible and coordinated disclosure, found a security vulnerability affecting sapia.com.pe website and...

0.2AI Score

2020-01-23 03:32 AM
8
openbugbounty
openbugbounty

monzapulita.it Improper Access Control vulnerability

Open Bug Bounty ID: OBB-1072221 Security Researcher 0xrocky Helped patch 1796 vulnerabilities Received 7 Coordinated Disclosure badges Received 5 recommendations , a holder of 7 badges for responsible and coordinated disclosure, found a security vulnerability affecting monzapulita.it website and...

6.7AI Score

2020-01-21 05:44 PM
8
openbugbounty
openbugbounty

patura.com Cross Site Scripting vulnerability

Security Researcher metamorfosec Helped patch 1911 vulnerabilities Received 9 Coordinated Disclosure badges Received 31 recommendations , a holder of 9 badges for responsible and coordinated disclosure, found a security vulnerability affecting patura.com website and its users. Following...

0.2AI Score

2020-01-21 06:25 AM
11
openbugbounty
openbugbounty

monpurse.com Cross Site Scripting vulnerability

Security Researcher 4N_CURZE Helped patch 1362 vulnerabilities Received 7 Coordinated Disclosure badges Received 12 recommendations , a holder of 7 badges for responsible and coordinated disclosure, found a security vulnerability affecting monpurse.com website and its users. Following...

0.1AI Score

2020-01-20 05:10 PM
9
huawei
huawei

Security Advisory - FragmentSmack Vulnerability in Linux Kernel

Products Switches Routers WLAN Storage See All Solutions Cloud Data Center Enterprise Networking Intelligent Computing Solutions by Industry See All Services Training and Certification Industry Cloud Enablement Service Improvement Service Customer Support Service See All Partner Find a Partner...

7.5CVSS

1.8AI Score

0.017EPSS

2020-01-15 12:00 AM
109
huawei
huawei

Security Advisory - FRP Bypass Vulnerability in Huawei Smart Phones

There is a Factory Reset Protection (FRP) bypass security vulnerability in some Huawei smart phones. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. As.....

4.6CVSS

5AI Score

0.001EPSS

2020-01-15 12:00 AM
60
openbugbounty
openbugbounty

mcsoares.pt Cross Site Scripting vulnerability

Open Bug Bounty ID: OBB-1067511 Security Researcher Gh05tPT Helped patch 6900 vulnerabilities Received 10 Coordinated Disclosure badges Received 48 recommendations , a holder of 10 badges for responsible and coordinated disclosure, found a security vulnerability affecting mcsoares.pt website and...

AI Score

2020-01-14 12:05 PM
9
openbugbounty
openbugbounty

sagliknotu.com Cross Site Scripting vulnerability

Security Researcher geeknik Helped patch 8635 vulnerabilities Received 8 Coordinated Disclosure badges Received 20 recommendations , a holder of 8 badges for responsible and coordinated disclosure, found a security vulnerability affecting sagliknotu.com website and its users. Following...

0.2AI Score

2020-01-09 06:22 PM
7
huawei
huawei

Security Advisory - Denial of Service Vulnerability in Several Smartphones

There is a denial of service vulnerability in several smartphones. The system does not properly check the status of certain module during certain operations, an attacker should trick the user into installing a malicious application, successful exploit could cause reboot of the smartphone....

5.5CVSS

5.3AI Score

0.001EPSS

2020-01-02 12:00 AM
55
huawei
huawei

Security Advisory - Integer Overflow Vulnerability in the Linux Kernel (SACK Panic)

An integer overflow vulnerability was found in the way the Linux kernel's networking subsystem processed TCP Selective Acknowledgment (SACK) segments. A remote attacker could use this to cause a denial of service. (Vulnerability ID: HWPSIRT-2019-06130) This vulnerability has been assigned a Common....

7.5CVSS

1.7AI Score

0.972EPSS

2019-12-26 12:00 AM
200
huawei
huawei

Security Advisory - Insufficient Input Validation Vulnerability in Some Huawei Products

There is an insufficient input validation vulnerability in some Huawei products. Due to incorrect input validation logic, a high-privilege attacker should bypass the device security detection mechanism, then modify the memory of the device by doing a series of operations. Successful exploit may...

9.8CVSS

8.9AI Score

0.002EPSS

2019-12-25 12:00 AM
96
openbugbounty
openbugbounty

b2d4ebe6468848a61f51-00a9605a715176e6bd23401c23e881d7.ssl.cf1.rackcdn.com Improper Access Control vulnerability

Open Bug Bounty ID: OBB-1040973 Security Researcher Gh05tPT Helped patch 6892 vulnerabilities Received 10 Coordinated Disclosure badges Received 48 recommendations , a holder of 10 badges for responsible and coordinated disclosure, found a security vulnerability affecting...

AI Score

2019-12-17 12:22 PM
7
openbugbounty
openbugbounty

modules.zef.pm Cross Site Scripting vulnerability

Open Bug Bounty ID: OBB-1040854 Following coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has: &nbsp&nbsp&nbsp&nbsp&nbsp&nbspa. verified the vulnerability and confirmed its existence; &nbsp&nbsp&nbsp&nbsp&nbsp&nbspb. notified the website...

-0.1AI Score

2019-12-17 07:40 AM
8
huawei
huawei

Security Advisory - Denial of Service Vulnerability on Some Huawei Smartphones

There is a denial of service vulnerability on some Huawei smartphones. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices to exploit this vulnerability....

6.5CVSS

6.1AI Score

0.001EPSS

2019-12-11 12:00 AM
44
huawei
huawei

Security Advisory - Information Disclosure Vulnerability in Several Smartphones

There is an information disclosure vulnerability in certain Huawei smartphones. The software does not properly handle certain information of application locked by applock in a rare condition, successful exploit could cause information disclosure. (Vulnerability ID: HWPSIRT-2018-08142) This...

4.6CVSS

4.4AI Score

0.001EPSS

2019-12-11 12:00 AM
26
huawei
huawei

Security Advisory - Path Traversal Vulnerability in Several Smartphones

There is a path traversal vulnerability in several smartphones. The system does not sufficiently validate certain pathname from the application, an attacker should trick the user into installing, backing up and restoring a malicious application, successful exploit could cause information...

5.5CVSS

5.1AI Score

0.001EPSS

2019-12-04 12:00 AM
59
huawei
huawei

Security Advisory - Use-after-free Vulnerability in Android Kernel

There is a use-after-free vulnerability in binder.c of Android kernel. Successful exploitation may cause the attacker elevate the privilege. (Vulnerability ID: HWPSIRT-2019-10100) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2019-2215. Huawei has...

7.8CVSS

6.9AI Score

0.003EPSS

2019-10-30 12:00 AM
92
openbugbounty
openbugbounty

securehotelsystem.com Cross Site Scripting vulnerability

Security Researcher metamorfosec Helped patch 1935 vulnerabilities Received 9 Coordinated Disclosure badges Received 31 recommendations , a holder of 9 badges for responsible and coordinated disclosure, found a security vulnerability affecting securehotelsystem.com website and its users. ...

0.2AI Score

2019-09-28 10:11 AM
8
huawei
huawei

Security Advisory - Key Negotiation of Bluetooth (KNOB) Vulnerability

The KNOB (Key Negotiation of Bluetooth) vulnerability exists in the encryption key negotiation process between two Bluetooth BR/EDR devices. The negotiation process is not encrypted and no authentication is performed. An unauthenticated, adjacent attacker can initiate a man-in-the-middle attack to....

8.1CVSS

8.4AI Score

0.001EPSS

2019-08-28 12:00 AM
101
openbugbounty
openbugbounty

mcsoares.pt Cross Site Scripting vulnerability

Open Bug Bounty ID: OBB-951087 Security Researcher Gh05tPT Helped patch 6892 vulnerabilities Received 10 Coordinated Disclosure badges Received 48 recommendations , a holder of 10 badges for responsible and coordinated disclosure, found a security vulnerability affecting mcsoares.pt website and...

0.1AI Score

2019-08-20 12:09 AM
7
cve
cve

CVE-2019-9506

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary...

8.1CVSS

8.8AI Score

0.001EPSS

2019-08-14 05:15 PM
403
3
openbugbounty
openbugbounty

visionauto.com.tw Cross Site Scripting vulnerability

Security Researcher Renzi Helped patch 6742 vulnerabilities Received 8 Coordinated Disclosure badges Received 36 recommendations , a holder of 8 badges for responsible and coordinated disclosure, found a security vulnerability affecting visionauto.com.tw website and its users. Following...

0.1AI Score

2019-07-26 07:30 AM
3
huawei
huawei

Security Advisory - MITM Vulnerability on Huawei Share

There is a man-in-the-middle(MITM) vulnerability on Huawei Share of certain smartphones. When users establish connection and transfer data through Huawei Share, an attacker could sniffer, spoof and do a series of operations to intrude the Huawei Share connection and launch a man-in-the-middle...

6.8CVSS

6AI Score

0.001EPSS

2019-05-17 12:00 AM
103
huawei
huawei

Security Advisory - FragmentSmack Vulnerability in Linux Kernel

There is a DoS vulnerability in the Linux Kernel versions 3.9+ known as a FragmentSmack attack. Remote attackers could send fragmented IPv4 or IPv6 packets to the affected device to trigger time and calculation reassembly algorithms that could consume excessive CPU resources, resulting in a DoS...

7.5CVSS

6.7AI Score

0.017EPSS

2019-01-23 12:00 AM
46
huawei
huawei

Security Advisory - Information Leak Vulnerability in Some Huawei Smartphones

There is an information leak vulnerability in some Huawei smartphones. An attacker may do some specific configuration in the smartphone and trick a user into inputting some sensitive information. Due to improper design, successful exploit may cause some information leak. (Vulnerability ID:...

4.3CVSS

4.7AI Score

0.001EPSS

2018-11-21 12:00 AM
20
huawei
huawei

Security Advisory - SegmentSmack Vulnerability in Linux Kernel

There is a DoS vulnerability in the Linux Kernel versions 4.9+ known as a SegmentSmack attack. Remote attackers may send TCP packets to Linux kernel to make it calls the very expensive functions tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() of the affected device which can lead to a denial of....

7.5CVSS

2.9AI Score

0.783EPSS

2018-10-31 12:00 AM
26
huawei
huawei

Security Advisory - SegmentSmack Vulnerability in Linux Kernel

There is a DoS vulnerability in the Linux Kernel versions 4.9+ known as a SegmentSmack attack. Remote attackers may send TCP packets to Linux kernel to make it calls the very expensive functions tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() of the affected device which can lead to a denial of....

7.5CVSS

7.2AI Score

0.783EPSS

2018-10-31 12:00 AM
48
huawei
huawei

Security Advisory - Improper Authentication Vulnerability on Smartphones

There is an improper authentication vulnerability on smartphones. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could directly change the lock password after a series of operations. Successful exploit could allow the attacker to use the application which is....

4.6CVSS

5.2AI Score

0.001EPSS

2018-10-10 12:00 AM
15
nvd
nvd

CVE-2018-7907

Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, Agassi-W09 AGS-W09C100B257CUSTC100D001, AGS-W09C128B252CUSTC128D001, AGS-W09C170B252CUSTC170D001, AGS-W09C229B251CUSTC229D001,...

5.5CVSS

5.2AI Score

0.001EPSS

2018-09-26 01:29 PM
cve
cve

CVE-2018-7907

Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, Agassi-W09 AGS-W09C100B257CUSTC100D001, AGS-W09C128B252CUSTC128D001, AGS-W09C170B252CUSTC170D001, AGS-W09C229B251CUSTC229D001,...

5.5CVSS

5.2AI Score

0.001EPSS

2018-09-26 01:29 PM
23
prion
prion

Information disclosure

Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, Agassi-W09 AGS-W09C100B257CUSTC100D001, AGS-W09C128B252CUSTC128D001, AGS-W09C170B252CUSTC170D001, AGS-W09C229B251CUSTC229D001,...

5.5CVSS

5.2AI Score

0.001EPSS

2018-09-26 01:29 PM
9
huawei
huawei

Security Advisory - Sensitive Information Leak Vulnerability in Some Huawei Products

There is a sensitive information leak vulnerability in some Huawei products. An attacker can trick a user to install a malicious application to exploit this vulnerability. Due to insufficient verification of the input, successful exploitation can cause sensitive information leak. (Vulnerability...

5.5CVSS

5.2AI Score

0.001EPSS

2018-09-19 12:00 AM
22
Total number of security vulnerabilities242