Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.2) | 0.47% | — | Huawei Mate 8 FirmwareHuawei P9 FirmwareHuawei P9 Plus Firmware | 1/6/2018 | 17/6/2026 | Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious parameters. An attacker may trick a target user into installing a malicious APK and launch attacks using a pre-installed app with specific permissions. Successful exploit could allow the app to send… | |
| Modificada | Alta (7.8) | 0.92% | — | Huawei Honor 6 FirmwareHuawei P9 Plus Firmware | 9/3/2018 | 17/6/2026 | Touchscreen drive in Huawei H60 (Honor 6) Versions earlier than H60-L02_6.12.16 and P9 Plus Versions earlier than VIE-AL10BC00B356 has a stack overflow vulnerabilities. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to touchscreen drive to crash the… | |
| Modificada | Alta (7.8) | 1.0% | — | Huawei P9 Plus Firmware | 22/11/2017 | 17/6/2026 | The soundtrigger driver in P9 Plus smart phones with software versions earlier than VIE-AL10BC00B353 has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can start multiple threads and try to free specific memory, which could triggers double… | |
| Modificada | Media (5.5) | 0.48% | — | Huawei P9 Plus Firmware | 22/11/2017 | 17/6/2026 | P9 Plus smartphones with software versions earlier before VIE-AL10BC00B386 have a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the application can send given parameter to specific interface, which make a large number of memory… | |
| Modificada | Media (5.5) | 0.55% | — | Huawei P9 Plus Firmware | 22/11/2017 | 17/6/2026 | The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone vibrator service interface to crash the system. | |
| Modificada | Media (5.5) | 0.65% | — | Huawei P9 Plus Firmware | 22/11/2017 | 17/6/2026 | P9 Plus smartphones with software earlier than VIE-AL10C00B352 versions have an input validation vulnerability in the touchscreen Driver. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone to crash the system. | |
| Modificada | Alta (7.8) | 0.81% | — | Huawei P9 FirmwareHuawei P9 Plus FirmwareHuawei Honor 6 Firmware | 2/4/2017 | 17/6/2026 | Video driver in Huawei P9 phones with software versions before EVA-AL10C00B192 and Huawei Honor 6 phones with software versions before H60-L02_6.10.1 has a stack overflow vulnerability, which allows attackers to crash the system or escalate user privilege. | |
| Modificada | Alta (7.8) | 0.81% | — | Huawei P9 FirmwareHuawei P9 Plus FirmwareHuawei Honor 6 Firmware | 2/4/2017 | 17/6/2026 | Touchscreen driver in Huawei P9 phones with software versions before EVA-AL10C00B192 and Huawei Honor 6 phones with software versions before H60-L02_6.10.1 has a heap overflow vulnerability, which allows attackers to crash the system or escalate user privilege. | |
| Modificada | Alta (7.8) | 0.81% | — | Huawei P9 FirmwareHuawei P9 Plus FirmwareHuawei Honor 6 Firmware | 2/4/2017 | 17/6/2026 | Video driver in Huawei P9 phones with software versions before EVA-AL10C00B192 and Huawei Honor 6 phones with software versions before H60-L02_6.10.1 has a stack overflow vulnerability, which allows attackers to crash the system or escalate user privilege. |