HTC's vulnerability profile centers on mobile devices and VR platforms spanning the EVO, Hero, and Droid Incredible smartphone lines as well as the Viveport VR ecosystem, a portfolio with broad consumer and enterprise reach. The vendor's disclosures cluster around information-exposure risks, certificate-validation issues, privilege-escalation weaknesses, and input-handling flaws typical of mobile and immersive platforms, and frequently acquire public exploit code. Live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Htc over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4295MEDIUM Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, whi | Sep 27, 2008 | 5.4 | 38 | NO | YES |
CVE-2008-6775HIGH HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consumption, and connectivity loss) via a flood of vCards to UDP p | May 1, 2009 | 7.1 | 28 | NO | YES |
CVE-2018-1170HIGH This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen Customer-Link App 1.30 and HTC Customer- | Mar 2, 2018 | 8.8 | 26 | NO | NO |
CVE-2019-12177HIGH Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges via DLL hi | Jun 3, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-12176HIGH Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfigu | Jun 3, 2019 | 7.8 | 24 | NO | NO |
CVE-2012-2980HIGH The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile | Aug 21, 2012 | 7.1 | 22 | NO | NO |
CVE-2012-2217MEDIUM The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D before 2.17.651.5, EVO View 4G before 2.23 | May 1, 2012 | 6.4 | 22 | NO | NO |
CVE-2007-3362HIGH ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of service (call disruption and device hang | Jun 22, 2007 | 7.8 | 22 | NO | NO |
CVE-2013-10001MEDIUM A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail client. An exploit has been dis | May 17, 2022 | 5.9 | 21 | NO | NO |
CVE-2013-4622HIGH The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote attackers to obtain access by leveraging | Jun 19, 2013 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Htc.
Media articles that mention a CVE ID that affects a product developed by Htc — matched by CVE ID, not by vendor name.