|
218791
|
5.9 |
MEDIUM
Network
|
huawei
|
e5572-855_firmware
|
E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient authentication when doing certain operations, successf…
|
CWE-287
Improper Authentication
|
CVE-2019-5253
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218792
|
5.5 |
MEDIUM
Local
|
huawei
|
ap2000_firmware ips_firmware ngfw_firmware nip6300_firmware nip6600_firmware nip6800_firmware s5700_firmware svn5600_firmware svn5800_firmware svn5800-c_firmware semg981…
|
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;US…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-5256
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218793
|
5.5 |
MEDIUM
Local
|
huawei
|
ap2000_firmware ips_firmware ngfw_firmware nip6300_firmware nip6600_firmware nip6800_firmware s5700_firmware svn5600_firmware svn5800_firmware svn5800-c_firmware semg981…
|
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;US…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5255
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218794
|
8.6 |
HIGH
Network
|
huawei
|
ap2000_firmware ips_firmware ngfw_firmware nip6300_firmware nip6600_firmware nip6800_firmware s5700_firmware svn5600_firmware svn5800_firmware svn5800-c_firmware semg981…
|
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;US…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5254
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218795
|
5.9 |
MEDIUM
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-5291
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218796
|
6.5 |
MEDIUM
Network
|
huawei
|
s5700_firmware s6700_firmware
|
Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations on affected devices. Because the pointer in the program is not processed prope…
|
NVD-CWE-noinfo
|
CVE-2019-5290
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218797
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_v10_firmware p30_firmware enjoy_7s_firmware mate_20_firmware honor_9_lite_firmware honor_9i_firmware m6_firmware p30_pro_firmware honor_20s_firmware
|
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installi…
|
CWE-22
Path Traversal
|
CVE-2019-5251
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218798
|
7.8 |
HIGH
Local
|
huawei
|
mate_20_pro_firmware
|
Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege,…
|
CWE-269
Improper Privilege Management
|
CVE-2019-5250
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218799
|
7.4 |
HIGH
Adjacent
|
huawei
|
cloudengine_12800_firmware
|
CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. A…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-5248
|
2024-11-21 13:44 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218800
|
8.8 |
HIGH
Network
|
kakadusoftware
|
kakadu_software
|
An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which c…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5144
|
2024-11-21 13:44 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|