huawei kayıtları
huawei üreticisine ait 2.340 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %0,1
- Silahlaştırılmış
- 4 · %0,2
- Pre-auth RCE
- 51
- Düzeltme kaydı olan
- %0,3
- Yayından KEV’e ortanca
- 754 gün
Tekrar eden sınıflar
- CWE-20 Improper Input Validation230
- CWE-125 Out-of-bounds Read147
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor110
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer109
- CWE-287 Improper Authentication87
- CWE-787 Out-of-bounds Write87
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
2.340 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-0708Silahlaştırılmış | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Kritik9,8 | KEV | %100,0 | 16 May 2019 |
83Hemen | CVE-2019-2215Silahlaştırılmış | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.google · android · CWE-416 | Yüksek7,8 | KEV | %72,1 | 11 Eki 2019 |
64Bu hafta | CVE-2017-14491Kavram kanıtı | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Kritik9,8 | — | %84,9 | 3 Eki 2017 |
61Bu hafta | CVE-2020-0069Silahlaştırılmış | In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization agoogle · android · CWE-787 | Yüksek7,8 | KEV | %1,4 | 10 Mar 2020 |
58Planlayın | CVE-2017-17215Kavram kanıtı | Huawei HG532 with some customized versions has a remote code execution vulnerability.huawei · hg532 firmware · CWE-20 | Yüksek8,8 | — | %78,3 | 20 Mar 2018 |
47Planlayın | CVE-2020-8840Kavram kanıtı | FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyedifasterxml · jackson-databind · CWE-502 | Kritik9,8 | — | %26,6 | 10 Şub 2020 |
41Planlayın | CVE-2016-8276İstismar yok | Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified securithuawei · usg2100 · CWE-119 | Kritik9,8 | — | %5,6 | 3 Eki 2016 |
41Planlayın | CVE-2017-3216İstismar yok | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remotegreenpacket · ox350 firmware · CWE-306 | Kritik9,8 | — | %5,2 | 19 Haz 2017 |
41Planlayın | CVE-2014-9134İstismar yok | Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to executehuawei · honor cube wireless router ws860s firewall | Kritik10,0 | — | %2,5 | 3 Ara 2014 |
41Planlayın | CVE-2012-6570İstismar yok | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S30huawei · ar 18-1x · CWE-119 | Kritik10,0 | — | %1,7 | 20 Haz 2013 |
40Planlayın | CVE-2016-6206İstismar yok | Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code vhuawei · ar3200 firmware · CWE-20 | Kritik9,8 | — | %3,8 | 24 Mar 2017 |
40Planlayın | CVE-2016-7109İstismar yok | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characterhuawei · uma · CWE-94 | Kritik9,8 | — | %3,5 | 7 Eyl 2016 |
40Planlayın | CVE-2016-6178İstismar yok | Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devichuawei · ne5000e firmware · CWE-20 | Kritik9,8 | — | %3,0 | 2 Ağu 2016 |
40Planlayın | CVE-2013-2612İstismar yok | Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with huawei · e587 firmware · CWE-78 | Kritik9,8 | — | %3,0 | 27 Oca 2020 |
40Planlayın | CVE-2016-7110İstismar yok | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characterhuawei · uma · CWE-94 | Kritik9,8 | — | %2,7 | 7 Eyl 2016 |
40Planlayın | CVE-2017-2738İstismar yok | VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability.huawei · vcm5010 firmware · CWE-287 | Kritik9,8 | — | %2,7 | 22 Kas 2017 |
40Planlayın | CVE-2016-4576İstismar yok | Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Shuawei · nip6300 · CWE-119 | Kritik9,8 | — | %2,4 | 23 May 2016 |
40Planlayın | CVE-2016-6825İstismar yok | Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPhuawei · rh1288 v3 server firmware · CWE-285 | Kritik9,8 | — | %2,1 | 7 Eyl 2016 |
40Planlayın | CVE-2015-7841İstismar yok | The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software huawei · fusionserver ch121 v3 · CWE-77 | Kritik9,8 | — | %2,1 | 2 Eki 2017 |
40Planlayın | CVE-2016-5365İstismar yok | Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary cohuawei · honor ws851 · CWE-264 | Kritik9,8 | — | %2,1 | 14 Haz 2016 |
40Planlayın | CVE-2015-4629İstismar yok | Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication,huawei · e5756s firmware · CWE-264 | Kritik9,8 | — | %1,7 | 7 Eyl 2017 |
40Planlayın | CVE-2009-2271İstismar yok | The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a huawei · d100 · CWE-255 | Kritik10,0 | — | %1,3 | 1 Tem 2009 |
40Planlayın | CVE-2026-34865İstismar yok | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confihuawei · harmonyos · CWE-122 | Kritik10,0 | — | %0,4 | 13 Nis 2026 |
39İzleyin | CVE-2019-19398İstismar yok | M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability.huawei · m5 lite 10 firmware · CWE-20 | Kritik9,8 | — | %1,4 | 26 Ara 2019 |
39İzleyin | CVE-2021-37095İstismar yok | There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remothuawei · harmonyos · CWE-190 | Kritik9,8 | — | %1,4 | 7 Ara 2021 |
- CVE-2019-070899Hemen
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100microsoft · windows 716 May 2019
- CVE-2019-221583Hemen
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %72google · android11 Eki 2019
- CVE-2017-1449164Bu hafta
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
KritikCVSS 9,8Kavram kanıtıEPSS %85thekelleys · dnsmasq3 Eki 2017
- CVE-2020-006961Bu hafta
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization a
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1google · android10 Mar 2020
- CVE-2017-1721558Planlayın
Huawei HG532 with some customized versions has a remote code execution vulnerability.
YüksekCVSS 8,8Kavram kanıtıEPSS %78huawei · hg532 firmware20 Mar 2018
- CVE-2020-884047Planlayın
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyedi
KritikCVSS 9,8Kavram kanıtıEPSS %27fasterxml · jackson-databind10 Şub 2020
- CVE-2016-827641Planlayın
Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified securit
KritikCVSS 9,8İstismar yokEPSS %6huawei · usg21003 Eki 2016
- CVE-2017-321641Planlayın
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote
KritikCVSS 9,8İstismar yokEPSS %5greenpacket · ox350 firmware19 Haz 2017
- CVE-2014-913441Planlayın
Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to execute
KritikCVSS 10,0İstismar yokEPSS %2huawei · honor cube wireless router ws860s firewall3 Ara 2014
- CVE-2012-657041Planlayın
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S30
KritikCVSS 10,0İstismar yokEPSS %2huawei · ar 18-1x20 Haz 2013
- CVE-2016-620640Planlayın
Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code v
KritikCVSS 9,8İstismar yokEPSS %4huawei · ar3200 firmware24 Mar 2017
- CVE-2016-710940Planlayın
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special character
KritikCVSS 9,8İstismar yokEPSS %4huawei · uma7 Eyl 2016
- CVE-2016-617840Planlayın
Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devic
KritikCVSS 9,8İstismar yokEPSS %3huawei · ne5000e firmware2 Ağu 2016
- CVE-2013-261240Planlayın
Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with
KritikCVSS 9,8İstismar yokEPSS %3huawei · e587 firmware27 Oca 2020
- CVE-2016-711040Planlayın
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special character
KritikCVSS 9,8İstismar yokEPSS %3huawei · uma7 Eyl 2016
- CVE-2017-273840Planlayın
VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability.
KritikCVSS 9,8İstismar yokEPSS %3huawei · vcm5010 firmware22 Kas 2017
- CVE-2016-457640Planlayın
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, S
KritikCVSS 9,8İstismar yokEPSS %2huawei · nip630023 May 2016
- CVE-2016-682540Planlayın
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SP
KritikCVSS 9,8İstismar yokEPSS %2huawei · rh1288 v3 server firmware7 Eyl 2016
- CVE-2015-784140Planlayın
The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software
KritikCVSS 9,8İstismar yokEPSS %2huawei · fusionserver ch121 v32 Eki 2017
- CVE-2016-536540Planlayın
Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary co
KritikCVSS 9,8İstismar yokEPSS %2huawei · honor ws85114 Haz 2016
- CVE-2015-462940Planlayın
Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication,
KritikCVSS 9,8İstismar yokEPSS %2huawei · e5756s firmware7 Eyl 2017
- CVE-2009-227140Planlayın
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a
KritikCVSS 10,0İstismar yokEPSS %1huawei · d1001 Tem 2009
- CVE-2026-3486540Planlayın
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confi
KritikCVSS 10,0İstismar yokEPSS %0huawei · harmonyos13 Nis 2026
- CVE-2019-1939839İzleyin
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1huawei · m5 lite 10 firmware26 Ara 2019
- CVE-2021-3709539İzleyin
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remot
KritikCVSS 9,8İstismar yokEPSS %1huawei · harmonyos7 Ara 2021