
CVE-2014-2271
https://notcve.org/view.php?id=CVE-2014-2271
14 Jan 2020 — cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic. cn.wps.moffice.common.beans.print.CloudPrintWebView en Kingsoft Office versión 5.3.1, como es usado en los dispositivo... • http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-401529.htm • CWE-20: Improper Input Validation •

CVE-2014-2273
https://notcve.org/view.php?id=CVE-2014-2273
05 Dec 2014 — The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary memory locations via unspecified vectors. El controlador de dispositivos hx170dec en Huawei P2-6011 anterior a V100R001C00B043 permite a usuarios locales leer y escribir a localizaciones de memoria arbitrarias a través de vectores no especificados. • http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-401529.htm • CWE-264: Permissions, Privileges, and Access Controls •