Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 11 of 56
CVE-2023-37240P3CRITICALCVSS 9.1v2.0.1v3.0.0+1 more2023-07-06
CVE-2023-37240 [CRITICAL] CWE-125 CVE-2023-37240: Vulnerability of missing input length verification in the distributed file system. Successful expl
Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read.
nvd
CVE-2022-48312P3CRITICALCVSS 9.1v2.0v2.0.02023-04-16
CVE-2022-48312 [CRITICAL] CWE-125 CVE-2022-48312: The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
nvd
CVE-2021-37086P3HIGHCVSS 8.6fixed in 2.0v2.02021-12-07
CVE-2021-37086 [HIGH] CWE-281 CVE-2021-37086: There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploi
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sandbox.
nvd
CVE-2025-48905P3HIGHCVSS 8.1v5.0.02025-06-06
CVE-2025-48905 [HIGH] CWE-1068 CVE-2025-48905: Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this
Wasm exception capture vulnerability in the arkweb v8 module
Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wasm exception types.
nvd
CVE-2024-42035P3HIGHCVSS 7.8v4.0.0v4.2.02024-08-08
CVE-2024-42035 [HIGH] CWE-862 CVE-2024-42035: Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this
Permission control vulnerability in the App Multiplier module
Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.
nvd
CVE-2021-37126P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37126 [HIGH] CWE-22 CVE-2021-37126: Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Succe
Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed.
nvd
CVE-2021-40012P3HIGHCVSS 7.5v2.02022-07-12
CVE-2021-40012 [HIGH] CVE-2021-40012: Vulnerability of pointers being incorrectly used during data transmission in the video framework. Su
Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2021-40063P3HIGHCVSS 7.5v2.02022-03-10
CVE-2021-40063 [HIGH] CVE-2021-40063: There is an improper access control vulnerability in the video module. Successful exploitation of th
There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2021-37133P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37133 [HIGH] CVE-2021-37133: There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vu
There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37113P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37113 [HIGH] CVE-2021-37113: There is a Privilege escalation vulnerability with the file system component in Smartphone.Successfu
There is a Privilege escalation vulnerability with the file system component in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-39969P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39969 [HIGH] CVE-2021-39969: There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vu
There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-39978P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39978 [HIGH] CWE-89 CVE-2021-39978: Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerabilit
Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy and security issues.
nvd
CVE-2022-22257P3HIGHCVSS 7.5v2.02022-04-11
CVE-2022-22257 [HIGH] CWE-269 CVE-2022-22257: The customization framework has a vulnerability of improper permission control.Successful exploitati
The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2022-34738P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34738 [HIGH] CVE-2022-34738: The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully
The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background.
nvd
CVE-2021-46812P3HIGHCVSS 7.5v2.02022-06-13
CVE-2021-46812 [HIGH] CVE-2021-46812: The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this
The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2023-46761P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46761 [HIGH] CWE-787 CVE-2023-46761: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46767P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46767 [HIGH] CWE-125 CVE-2023-46767: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46762P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46762 [HIGH] CWE-125 CVE-2023-46762: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46760P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46760 [HIGH] CWE-787 CVE-2023-46760: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46766P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46766 [HIGH] CWE-125 CVE-2023-46766: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd