VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202110-1491 CVE-2021-22491 Huawei  Input validation vulnerability in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. Huawei Smartphones contain a vulnerability related to input validation.Service operation interruption (DoS) It may be in a state
VAR-202110-1490 CVE-2021-36985 Huawei  Code injection vulnerability in smartphones CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart. Huawei Smartphones have a code injection vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202110-1489 CVE-2021-36986 Huawei  Vulnerabilities in smartphones CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. Huawei Smartphones have unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202110-1487 CVE-2021-36988 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Parameter verification issue in Huawei Smartphone.Successful exploitation of this vulnerability can affect service integrity. Huawei Smartphones have unspecified vulnerabilities.Information may be tampered with
VAR-202110-1488 CVE-2021-36987 Huawei  Race Condition Vulnerability in Smartphones CVSS V2: 7.1
CVSS V3: 5.9
Severity: MEDIUM
There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart. Huawei Smartphones contain a race condition vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202110-1486 CVE-2021-36990 Huawei  Improper Default Permission Vulnerability in Smartphones CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. Huawei Smartphones are vulnerable to improper default permissions.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202110-1485 CVE-2021-36991 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is an Unauthorized file access vulnerability in Huawei Smartphone due to unstandardized path input.Successful exploitation of this vulnerability by creating malicious file paths can cause unauthorized file access. Huawei Smartphones have unspecified vulnerabilities.Information may be obtained
VAR-202110-1481 CVE-2021-36995 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tamper with the files restored from backups. Huawei Smartphones have unspecified vulnerabilities.Information may be tampered with
VAR-202110-1483 CVE-2021-36993 Huawei  Vulnerability related to lack of freeing memory after expiration in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. Huawei There is a vulnerability in smartphones related to lack of free memory after expiration.Service operation interruption (DoS) It may be in a state
VAR-202110-1482 CVE-2021-36994 Huawei  Race Condition Vulnerability in Smartphones CVSS V2: 4.3
CVSS V3: 3.7
Severity: LOW
There is a issue that trustlist strings being repeatedly inserted into the linked list in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause exceptions when managing the system trustlist. Huawei Smartphones contain a race condition vulnerability.Information may be tampered with
VAR-202110-1480 CVE-2021-36996 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of certain virtual information. Huawei Smartphones have unspecified vulnerabilities.Information may be obtained
VAR-202110-1479 CVE-2021-36997 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
There is a Low memory error in Huawei Smartphone due to the unlimited size of images to be parsed.Successful exploitation of this vulnerability may cause the Gallery or Files app to exit unexpectedly. Huawei Smartphones have unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
VAR-202110-1477 CVE-2021-36999 Huawei  smartphone   classic buffer overflow vulnerability in CVSS V2: 6.8
CVSS V3: 7.8
Severity: HIGH
There is a Buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by sending malicious images and inducing users to open the images may cause remote code execution. Huawei Smartphones have a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei Smartphone is a smartphone of the Chinese company Huawei (Huawei). Successful exploitation could lead to remote code execution
VAR-202110-1478 CVE-2021-36998 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to read an array that is out of bounds. Huawei Smartphones have unspecified vulnerabilities.Information may be obtained. Huawei Smartphone is a smartphone of the Chinese company Huawei (Huawei)
VAR-202110-1476 CVE-2021-37001 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Register tampering vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow the register value to be modified. Huawei Smartphones have unspecified vulnerabilities.Information may be tampered with. Huawei Smartphone is a smartphone of the Chinese company Huawei (Huawei)
VAR-202110-1475 CVE-2021-37002 Huawei  Buffer Error Vulnerability in Smartphones CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
There is a Memory out-of-bounds access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed. Huawei Smartphones contain a buffer error vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202110-1460 CVE-2021-22451 HarmonyOS  Integer overflow vulnerability in CVSS V2: 4.6
CVSS V3: 7.8
Severity: HIGH
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting. HarmonyOS Exists in an integer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202110-1459 CVE-2021-22454 HarmonyOS  Vulnerability in leaking resources to the wrong area in CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump. HarmonyOS Exists in a vulnerability related to the leakage of resources to the wrong area.Service operation interruption (DoS) It may be in a state
VAR-202110-1458 CVE-2021-22461 HarmonyOS  Vulnerability in resource allocation without restrictions or throttling in CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash
VAR-202110-1456 CVE-2021-22463 HarmonyOS  Vulnerability in using free memory in CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure