
CVE-2017-17176
https://notcve.org/view.php?id=CVE-2017-17176
17 Oct 2018 — The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B156, versions earlier before MHA-CL00BC00B156, versions earlier before MHA-DL00BC00B156, versions earlier before MHA-TL00BC00B156, versions earlier before LON-AL00BC00B156, versions earlier before LON-CL00BC00B156, versions earlier before LON-DL00BC00B156, versions earlier before LON-TL00BC00B156 has a arbitrary memory read/write vulnerability due to the input parameters validation. An att... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170306-01-smartphone-en • CWE-787: Out-of-bounds Write •

CVE-2018-7930
https://notcve.org/view.php?id=CVE-2018-7930
11 Apr 2018 — The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vulnerability due to insufficient validation on data transfer requests. When an affected mobile phone sends files to an attacker's mobile phone using the NFC function, the attacker can obtain arbitrary files from the mobile phone, causing information leaks. El módulo Near Field Communication (NFC) en los teléfonos móviles Mate 9 Huawei con versiones anteriores a ... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180411-01-smartphone-en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-17139
https://notcve.org/view.php?id=CVE-2017-17139
05 Mar 2018 — Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions before LON-AL00B 8.0.0.334(C00) have a information leak vulnerability in the date service proxy implementation. An attacker may trick a user into installing a malicious application and application can exploit the vulnerability to get kernel date which may cause sensitive information leak. Los smartphones Huawei Mate 9 y Mate 9 pro con software en versiones anteriores a la MHA-AL00B 8.0.0.334(C0... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171213-04-smartphone-en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-8165
https://notcve.org/view.php?id=CVE-2017-8165
05 Mar 2018 — Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Successful exploitation may cause sensitive information leak. Los smartphones Huawei Mate 9 con versiones anteriores a la MHA-AL00BC00B233 tienen una vulnerabilidad de filtrado de información sensible. Un atacante puede engañar a un usuario para que instale una aplicación maliciosa para explotar ... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171117-01-smartphone-en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-15311
https://notcve.org/view.php?id=CVE-2017-15311
22 Dec 2017 — The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range by special wireless device, which leads stack overflow when the baseband module handles these packets. The attacker c... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171125-01-baseband-en • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-15316 – Huawei Mate 9 Pro Mali Double Free Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2017-15316
22 Dec 2017 — The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which triggers double free and causes a system crash or arbitrary code execution. El controlador de unidad de procesamiento gráfico o GPU de los smartphones Mate 9de Huawei con software anter... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171201-01-smartphone-en • CWE-415: Double Free •

CVE-2017-2702
https://notcve.org/view.php?id=CVE-2017-2702
22 Nov 2017 — Phone Finder in versions earlier before MHA-AL00C00B170 can be bypass. An attacker can bypass the Phone Finder by special steps and obtain the owner of the phone. Puede eludirse Phone Finder en versiones anteriores a la MHA-AL00C00B170. Un atacante puede eludir Phone Finder mediante pasos especiales y obtener la titularidad del teléfono. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170322-01-smartphone-en •

CVE-2017-2703
https://notcve.org/view.php?id=CVE-2017-2703
22 Nov 2017 — Phone Finder in versions earlier before MHA-AL00BC00B156,Versions earlier before MHA-CL00BC00B156,Versions earlier before MHA-DL00BC00B156,Versions earlier before MHA-TL00BC00B156,Versions earlier before EVA-AL10C00B373,Versions earlier before EVA-CL10C00B373,Versions earlier before EVA-DL10C00B373,Versions earlier before EVA-TL10C00B373 can be bypass. An attacker can bypass the Phone Finder by special steps and enter the System Setting. Puede eludirse Phone Finder en versiones anteriores a la MHA-AL00BC00B... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170118-05-smartphone-en •

CVE-2017-2706
https://notcve.org/view.php?id=CVE-2017-2706
22 Nov 2017 — Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module. Since the system does not verify the file name during decompression, system directories are traversed. It could be exploited to cause the attacker to replace files and impact the service. Los smartphones Mate 9 con software MHA-AL00AC00B125 tienen una vulnerabilidad de salto de directorio en el módulo Push. Debido a que el sistema no verifica el nombre de archivo durante la descompresión, los directori... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170712-01-push-en • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2017-2707
https://notcve.org/view.php?id=CVE-2017-2707
22 Nov 2017 — Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to cause the attacker to delete message or fake user to send message. Los smartphones Mate 9 con software MHA-AL00AC00B125 tienen una vulnerabilidad de escalado de privilegios en el módulo Push. Un atacante engaña a un usuario para que guarde medios enriquecidos (rich media) en un mensaje del smart... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170712-02-push-en • CWE-494: Download of Code Without Integrity Check •