CVE-2017-17320
https://notcve.org/view.php?id=CVE-2017-17320
Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188 have a memory double free vulnerability. The system does not manage the memory properly, that frees on the same memory address twice. An attacker tricks the user who has root privilege to install a crafted application, successful exploit could result in malicious code execution. Los smartphones Huawei Mate 9 Pro con software LON-AL00BC00B139D, LON-AL00BC00B229 y LON-L29DC721B188 tienen una vulnerabilidad de doble liberación (double free) de memoria. El sistema no gestiona la memoria correctamente, ya que libera dos veces en la misma dirección de memoria. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180314-02-smartphone-en • CWE-415: Double Free •
CVE-2017-17279
https://notcve.org/view.php?id=CVE-2017-17279
The soundtrigger module in Huawei Mate 9 Pro smart phones with software of the versions before LON-AL00B 8.0.0.343(C00) has an authentication bypass vulnerability due to the improper design of the module. An attacker tricks a user into installing a malicious application, and the application can exploit the vulnerability and make attacker bypass the authentication, the attacker can control the phone to sent short messages and make call within audio range to the phone. El módulo soundtrigger en los smartphones Huawei Mate 9 Pro, con software en versiones anteriores a la LON-AL00B 8.0.0.343(C00), tiene una vulnerabilidad de omisión de autenticación debido al diseño incorrecto del módulo. Un atacante engaña a un usuario para que instale una aplicación maliciosa, que puede explotar la vulnerabilidad y hacer que el atacante omita la autenticación, controle el teléfono para enviar mensajes cortos y hacer llamadas en el rango de audio al teléfono. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180307-01-smartphone-en http://www.securityfocus.com/bid/103360 •
CVE-2017-17324
https://notcve.org/view.php?id=CVE-2017-17324
Huawei Mate 9 Pro smartphones with software LON-AL00BC00B139D; LON-AL00BC00B229 have an integer overflow vulnerability. The camera driver does not validate the external input parameters and causes an integer overflow, which in the after processing results in a buffer overflow. An attacker tricks the user to install a crafted application, successful exploit could cause malicious code execution. Los smartphones Huawei Mate 9 Pro con software LON-AL00BC00B139D y LON-AL00BC00B229 tienen una vulnerabilidad de desbordamiento de enteros. El controlador de la cámara no valida los parámetros de entradas externas y provoca un desbordamiento de enteros, que tras el posprocesado resulta en un desbordamiento de búfer. • http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180124-01-smartphone-en • CWE-190: Integer Overflow or Wraparound •
CVE-2017-17326
https://notcve.org/view.php?id=CVE-2017-17326
Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient protection of activation lock. Successful exploit could allow an attacker to bypass the activation lock and activate the smartphone by a new account after a series of operation. Los smartphones Huawei Mate 9 Pro con software LON-AL00BC00B139D y LON-AL00BC00B229 tienen una vulnerabilidad de omisión de bloqueo de activación. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171227-01-smartphone-en •
CVE-2017-17225
https://notcve.org/view.php?id=CVE-2017-17225
The Near Field Communication (NFC) module in Huawei Mate 9 Pro mobile phones with the versions before LON-AL00B 8.0.0.340a(C00) has a buffer overflow vulnerability due to the lack of input validation. An attacker may use an NFC card reader or another device to inject malicious data into a target mobile phone. Successful exploit could lead to system restart or arbitrary code execution. El módulo NFC (Near Field Communication) en los smartphones Huawei Mate 9 Pro con versiones anteriores a LON-AL00B 8.0.0.340a(C00) tiene una vulnerabilidad de desbordamiento de búfer debido a la falta de validación de entradas. Un atacante podría emplear un lector de tarjetas NFC u otro dispositivo para inyectar datos maliciosos en un teléfono móvil objetivo. • http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180130-01-smartphone-en • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •