Unknown · CVSS Not scored
UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
Published Aug 10, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).
Published Aug 10, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulnerability affects versions 10.10, 10.20, 10.30, 10.40, 10.50, 10.60, 10.70, 10.80, 10.0 and 10.91. A privileged user may potentially misuse this feature and thus allow unintended and unauthorized access of data.
Published Aug 5, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations. Affected product versions include: Hulk-AL00C 9.1.1.201(C00E201R8P1);Jennifer-AN00C 10.1.1.171(C00E170R6P3);Jenny-AL10B 10.1.0.228(C00E220R5P1) and OxfordPL-AN10B 10.1.0.116(C00E110R2P1).
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Incorrect Calculation of Buffer Size in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a Heap-based Buffer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a Memory Buffer Errors Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
Published Aug 10, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause code injection.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Improper Check for Unusual or Exceptional Conditions Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful exploit could allow an attacker to add users to be friends without prompting in the target device.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escalation.Affected product versions include:eCNS280_TD V100R005C00,V100R005C10;eSE620X vESS V100R001C10SPC200,V100R001C20SPC200.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause random kernel address access.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Incomplete Cleanup Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause random address access.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Incorrect Calculation of Buffer Size Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause kernel exceptions with the code.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a Configuration Defect Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these files to cause privilege escalation attack. This can compromise normal service.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Improper Validation of Integrity Check Value Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the system to reset.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The app can modify specific parameters, causing the system to crash. Affected product include:OxfordS-AN00A 10.0.1.10(C00E10R1P1),10.0.1.105(C00E103R3P3),10.0.1.115(C00E110R3P3),10.0.1.123(C00E121R3P3),10.0.1.135(C00E130R3P3),10.0.1.135(C00E130R4P1),10.0.1.152(C00E140R4P1),10.0.1.160(C00E160R4P1),10.0.1.167(C00E166R4P1),10.0.1.173(C00E172R5P1),10.0.1.178(C00E175R5P1) and 10.1.0.202(C00E79R5P1).
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Incorrect Calculation of Buffer Size in Huawei Smartphone.Successful exploitation of this vulnerability may cause verification bypass and directions to abnormal addresses.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Integer Underflow (Wrap or Wraparound) Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause DoS of Samgr.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Input Verification Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause an infinite loop in DoS.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to remotely execute commands.
Published Aug 2, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges.
Published Aug 10, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages due to validating inputs insufficiently. Attackers can exploit this vulnerability by sending specific messages to affected module. This can cause denial of service. Affected product versions include: S12700 V200R013C00SPC500, V200R019C00SPC500; S5700 V200R013C00SPC500, V200R019C00SPC500; S6700 V200R013C00SPC500, V200R019C00SPC500; S7700 V200R013C00SPC500, V200R019C00SPC500.
Published Aug 23, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft the specific packet. Successful exploit may cause some services abnormal. Affected product versions include:CloudEngine 12800 V200R005C00SPC800, CloudEngine 5800 V200R005C00SPC800, CloudEngine 6800 V200R005C00SPC800, CloudEngine 7800 V200R005C00SPC800.
Published Aug 23, 2021 · Updated Aug 3, 2024
Low · CVSS 3.1
Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE 13.1 and later through 14.1.2, 14.0.7 and 13.12.9.
Published Aug 20, 2021 · Updated Aug 3, 2024
High · CVSS 7.7
SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.
Published Aug 20, 2021 · Updated Aug 3, 2024
High · CVSS 8.3
Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.
Published Aug 11, 2022 · Updated Aug 3, 2024
Medium · CVSS 5.4
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
Published Aug 25, 2021 · Updated Aug 3, 2024
Medium · CVSS 6.6
Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions before 13.12.9, 14.0.7, 14.1.2
Published Aug 25, 2021 · Updated Aug 3, 2024