
CVE-2020-9089
https://notcve.org/view.php?id=CVE-2020-9089
27 Dec 2024 — There is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. Attackers with user access can exploit this vulnerability to obtain some information. This can lead to information leak. (Vulnerability ID: HWPSIRT-2019-12141) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9089. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200826-09-smartphone-en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2020-9081
https://notcve.org/view.php?id=CVE-2020-9081
27 Dec 2024 — There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081. • https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20200826-15-smartphone-en • CWE-285: Improper Authorization •

CVE-2020-9247
https://notcve.org/view.php?id=CVE-2020-9247
07 Dec 2020 — There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-9106
https://notcve.org/view.php?id=CVE-2020-9106
12 Oct 2020 — HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and cause information disclosure. Dispositivos HUAWEI P30 Pro versiones anteriores a 10.1.0.160(C00E160R2P8), presentan una vulnerabilidad de salto de ruta. El sistema no comprueba suficientemente determinado nombre de ruta, una explotación con éxito podría permitir al atacante acceder a arc... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200930-01-pathtraversal-en • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2020-9123
https://notcve.org/view.php?id=CVE-2020-9123
12 Oct 2020 — HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) and versions earlier than 10.1.0.160(C01E160R2P8) have a buffer overflow vulnerability. An attacker induces users to install malicious applications and sends specially constructed packets to affected devices after obtaining the root permission. Successful exploit may cause code execution. Dispositivos HUAWEI P30 Pro versiones anteriores a 10.1.0.160(C00E160R2P8) y versiones anteriores a 10.1.0.160(C01E160R2P8), presentan una vulnerabilidad de desb... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200930-01-buffer-en • CWE-787: Out-of-bounds Write •

CVE-2020-9109
https://notcve.org/view.php?id=CVE-2020-9109
12 Oct 2020 — There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack, and successful exploit could cause information disclosure.Affected product versions include:HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8),versions earlier than 10.1.0.160(C01E160R2P8);HUAWEI Mate 20 X versions earlier t... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200930-01-dos-en • CWE-287: Improper Authentication •

CVE-2020-9107
https://notcve.org/view.php?id=CVE-2020-9107
12 Oct 2020 — HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the process reboot. Dispositivos HUAWEI P30 Pro versiones anteriores a 10.1.0.160(C00E160R2P8), presentan una vulnerabilidad de lectura y escritura fuera de límites. Un atacante no autenticado d... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200930-01-readwriteoutbound-en • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •

CVE-2020-9108
https://notcve.org/view.php?id=CVE-2020-9108
12 Oct 2020 — HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the process reboot. Dispositivos HUAWEI P30 Pro versiones anteriores a 10.1.0.160(C00E160R2P8), presentan una vulnerabilidad de lectura y escritura fuera de límites. Un atacante no autenticado d... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200930-01-outofbound-en • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •

CVE-2020-9095
https://notcve.org/view.php?id=CVE-2020-9095
21 Aug 2020 — HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause integer overflow. This can compromise normal service. El teléfono inteligente HUAWEI P30 Pro con versiones anteriores a 10.1.0.160(C00E160R2P8), presenta una vulnerabilidad de desbordamiento de enteros. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200819-03-smartphone-en • CWE-190: Integer Overflow or Wraparound •

CVE-2020-9096
https://notcve.org/view.php?id=CVE-2020-9096
21 Aug 2020 — HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service. Los teléfonos inteligentes HUAWEI P30 Pro con versiones anteriores a 10.1.0.160(C00E160R2P8), presentan una vulnerabilidad de lectura fuera de límites. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200819-02-smartphone-en • CWE-125: Out-of-bounds Read •