Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 12 of 56
CVE-2022-41589P3HIGHCVSS 7.5v2.02022-10-14
CVE-2022-41589 [HIGH] CWE-703 CVE-2022-41589: The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful e
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability.
nvd
CVE-2021-40040P3HIGHCVSS 7.5v2.02022-08-10
CVE-2021-40040 [HIGH] CVE-2021-40040: Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploit
Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48359P3HIGHCVSS 7.5v2.0v2.0.1+4 more2023-03-27
CVE-2022-48359 [HIGH] CWE-915 CVE-2022-48359: The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successfu
The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-49244P3HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-49244 [HIGH] CVE-2023-49244: Permission management vulnerability in the multi-user module. Successful exploitation of this vulner
Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-30417P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-07
CVE-2024-30417 [HIGH] CWE-22 CVE-2024-30417: Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation
Path traversal vulnerability in the Bluetooth-based sharing module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44113P3HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-44113 [HIGH] CWE-862 CVE-2023-44113: Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) modu
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46759P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46759 [HIGH] CWE-284 CVE-2023-46759: Permission control vulnerability in the call module. Successful exploitation of this vulnerability m
Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48299P3HIGHCVSS 7.5v2.0v3.0.02023-02-09
CVE-2022-48299 [HIGH] CWE-306 CVE-2022-48299: The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vuln
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48300P3HIGHCVSS 7.5v2.0v3.0.02023-02-09
CVE-2022-48300 [HIGH] CWE-306 CVE-2022-48300: The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vuln
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48360P3HIGHCVSS 7.5v2.0.0v2.1.0+1 more2023-03-27
CVE-2022-48360 [HIGH] CWE-276 CVE-2022-48360: The facial recognition module has a vulnerability in file permission control. Successful exploitatio
The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48297P3HIGHCVSS 7.5v2.0v3.0.02023-02-09
CVE-2022-48297 [HIGH] CWE-1284 CVE-2022-48297: The geofencing kernel code has a vulnerability of not verifying the length of the input data. Succes
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2022-48514P3HIGHCVSS 7.5v2.1.02023-07-06
CVE-2022-48514 [HIGH] CWE-200 CVE-2022-48514: The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitati
The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-52100P3HIGHCVSS 7.5v4.0.02024-01-16
CVE-2023-52100 [HIGH] CVE-2023-52100: The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vul
The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-53169P3HIGHCVSS 7.6v5.0.1v5.1.02025-07-07
CVE-2025-53169 [HIGH] CWE-287 CVE-2025-53169: Vulnerability of bypassing the process to start SA and use related functions on distributed cameras
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras
Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
nvd
CVE-2023-31227P3HIGHCVSS 7.5v3.1.0v3.0.0+1 more2023-05-26
CVE-2023-31227 [HIGH] CWE-306 CVE-2023-31227: The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of th
The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality.
nvd
CVE-2023-44104P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44104 [HIGH] CWE-669 CVE-2023-44104: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44100P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-10-11
CVE-2023-44100 [HIGH] CWE-669 CVE-2023-44100: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41301P3HIGHCVSS 7.5v2.0.0v2.0.1+2 more2023-09-25
CVE-2023-41301 [HIGH] CWE-269 CVE-2023-41301: Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerab
Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-44101P3HIGHCVSS 7.5v2.0.0v2.1.0+2 more2023-10-11
CVE-2023-44101 [HIGH] CWE-668 CVE-2023-44101: The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successfu
The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-44093P3HIGHCVSS 7.5v2.0v2.0.1+4 more2023-10-11
CVE-2023-44093 [HIGH] CWE-200 CVE-2023-44093: Vulnerability of package names' public keys not being verified in the security module.Successful exp
Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd