cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 11 of 56
CVE-2023-37240P3CRITICALCVSS 9.1v2.0.1v3.0.0+1 more2023-07-06
CVE-2023-37240 [CRITICAL] CWE-125 CVE-2023-37240: Vulnerability of missing input length verification in the distributed file system. Successful expl Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read.
nvd
CVE-2022-48312P3CRITICALCVSS 9.1v2.0v2.0.02023-04-16
CVE-2022-48312 [CRITICAL] CWE-125 CVE-2022-48312: The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
nvd
CVE-2021-37086P3HIGHCVSS 8.6fixed in 2.0v2.02021-12-07
CVE-2021-37086 [HIGH] CWE-281 CVE-2021-37086: There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploi There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sandbox.
nvd
CVE-2025-48905P3HIGHCVSS 8.1v5.0.02025-06-06
CVE-2025-48905 [HIGH] CWE-1068 CVE-2025-48905: Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wasm exception types.
nvd
CVE-2024-42035P3HIGHCVSS 7.8v4.0.0v4.2.02024-08-08
CVE-2024-42035 [HIGH] CWE-862 CVE-2024-42035: Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.
nvd
CVE-2021-37126P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37126 [HIGH] CWE-22 CVE-2021-37126: Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Succe Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed.
nvd
CVE-2021-40012P3HIGHCVSS 7.5v2.02022-07-12
CVE-2021-40012 [HIGH] CVE-2021-40012: Vulnerability of pointers being incorrectly used during data transmission in the video framework. Su Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2021-40063P3HIGHCVSS 7.5v2.02022-03-10
CVE-2021-40063 [HIGH] CVE-2021-40063: There is an improper access control vulnerability in the video module. Successful exploitation of th There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2021-37133P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37133 [HIGH] CVE-2021-37133: There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vu There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37113P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37113 [HIGH] CVE-2021-37113: There is a Privilege escalation vulnerability with the file system component in Smartphone.Successfu There is a Privilege escalation vulnerability with the file system component in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-39969P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39969 [HIGH] CVE-2021-39969: There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vu There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-39978P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39978 [HIGH] CWE-89 CVE-2021-39978: Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerabilit Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy and security issues.
nvd
CVE-2022-22257P3HIGHCVSS 7.5v2.02022-04-11
CVE-2022-22257 [HIGH] CWE-269 CVE-2022-22257: The customization framework has a vulnerability of improper permission control.Successful exploitati The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2022-34738P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34738 [HIGH] CVE-2022-34738: The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background.
nvd
CVE-2021-46812P3HIGHCVSS 7.5v2.02022-06-13
CVE-2021-46812 [HIGH] CVE-2021-46812: The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2023-46761P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46761 [HIGH] CWE-787 CVE-2023-46761: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46767P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46767 [HIGH] CWE-125 CVE-2023-46767: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46762P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46762 [HIGH] CWE-125 CVE-2023-46762: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46760P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46760 [HIGH] CWE-787 CVE-2023-46760: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46766P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46766 [HIGH] CWE-125 CVE-2023-46766: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
Huawei Harmonyos vulnerabilities | cvebase