|
250301
|
6.5 |
MEDIUM
Network
|
huawei
|
dp300_firmware
|
The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote …
|
CWE-20
Improper Input Validation
|
CVE-2017-17168
|
2024-11-21 12:17 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250302
|
7.8 |
HIGH
Local
|
huawei
|
dp300_firmware
|
Huawei DP300 V500R002C00 have a buffer overflow vulnerability due to the lack of validation. An authenticated local attacker can craft specific XML files to the affected products and parse this file,…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17146
|
2024-11-21 12:17 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250303
|
4.6 |
MEDIUM
Physics
|
huawei
|
honor_v9_play_firmware
|
Huawei Honor V9 Play smart phones with the versions before Jimmy-AL00AC00B135 have an authentication bypass vulnerability due to the improper design of a component. An attacker who get a user's smart…
|
NVD-CWE-noinfo
|
CVE-2017-17145
|
2024-11-21 12:17 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250304
|
5.5 |
MEDIUM
Local
|
huawei
|
dp300_firmware rp200_firmware te30_firmware te40_firmware te50_firmware te60_firmware
|
Timergrp module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-17150
|
2024-11-21 12:17 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250305
|
5.5 |
MEDIUM
Local
|
huawei
|
enjoy_5s_firmware y6_pro_firmware
|
Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter valid…
|
CWE-200
Information Exposure
|
CVE-2017-17140
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250306
|
5.5 |
MEDIUM
Local
|
huawei
|
mate_9_pro_firmware mate_9_firmware
|
Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions before LON-AL00B 8.0.0.334(C00) have a information leak vulnerability in the date se…
|
CWE-200
Information Exposure
|
CVE-2017-17139
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250307
|
5.3 |
MEDIUM
Network
|
huawei
|
dp300_firmware rp200_firmware rse6500_firmware te30_firmware te40_firmware te50_firmware te60_firmware tp3106_firmware tp3206_firmware viewpoint_9030_firmware espace_u19…
|
Backup feature of SIP module in Huawei DP300 V500R002C00; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800; V500R002…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17144
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250308
|
5.3 |
MEDIUM
Network
|
huawei
|
dp300_firmware rp200_firmware rse6500_firmware te30_firmware te40_firmware te50_firmware te60_firmware tp3106_firmware tp3206_firmware viewpoint_9030_firmware espace_u19…
|
SIP module in Huawei DP300 V500R002C00; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800; V500R002C00SPC900; V500R00…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17143
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250309
|
5.5 |
MEDIUM
Local
|
huawei
|
vp9660_firmware
|
Huawei VP9660 V500R002C10 has a null pointer reference vulnerability in license module due to insufficient verification. An authenticated local attacker could place a malicious license file into syst…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-17133
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250310
|
5.5 |
MEDIUM
Local
|
huawei
|
vp9660_firmware
|
Huawei VP9660 V500R002C10 has a uncontrolled format string vulnerability when the license module output the log information. An authenticated local attacker could exploit this vulnerability to cause …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2017-17132
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|