cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 12 of 56
CVE-2022-41589P3HIGHCVSS 7.5v2.02022-10-14
CVE-2022-41589 [HIGH] CWE-703 CVE-2022-41589: The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful e The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability.
nvd
CVE-2021-40040P3HIGHCVSS 7.5v2.02022-08-10
CVE-2021-40040 [HIGH] CVE-2021-40040: Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploit Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48359P3HIGHCVSS 7.5v2.0v2.0.1+4 more2023-03-27
CVE-2022-48359 [HIGH] CWE-915 CVE-2022-48359: The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successfu The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-49244P3HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-49244 [HIGH] CVE-2023-49244: Permission management vulnerability in the multi-user module. Successful exploitation of this vulner Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-30417P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-07
CVE-2024-30417 [HIGH] CWE-22 CVE-2024-30417: Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44113P3HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-44113 [HIGH] CWE-862 CVE-2023-44113: Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) modu Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46759P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46759 [HIGH] CWE-284 CVE-2023-46759: Permission control vulnerability in the call module. Successful exploitation of this vulnerability m Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48299P3HIGHCVSS 7.5v2.0v3.0.02023-02-09
CVE-2022-48299 [HIGH] CWE-306 CVE-2022-48299: The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vuln The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48300P3HIGHCVSS 7.5v2.0v3.0.02023-02-09
CVE-2022-48300 [HIGH] CWE-306 CVE-2022-48300: The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vuln The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48360P3HIGHCVSS 7.5v2.0.0v2.1.0+1 more2023-03-27
CVE-2022-48360 [HIGH] CWE-276 CVE-2022-48360: The facial recognition module has a vulnerability in file permission control. Successful exploitatio The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48297P3HIGHCVSS 7.5v2.0v3.0.02023-02-09
CVE-2022-48297 [HIGH] CWE-1284 CVE-2022-48297: The geofencing kernel code has a vulnerability of not verifying the length of the input data. Succes The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2022-48514P3HIGHCVSS 7.5v2.1.02023-07-06
CVE-2022-48514 [HIGH] CWE-200 CVE-2022-48514: The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitati The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-52100P3HIGHCVSS 7.5v4.0.02024-01-16
CVE-2023-52100 [HIGH] CVE-2023-52100: The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vul The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-53169P3HIGHCVSS 7.6v5.0.1v5.1.02025-07-07
CVE-2025-53169 [HIGH] CWE-287 CVE-2025-53169: Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
nvd
CVE-2023-31227P3HIGHCVSS 7.5v3.1.0v3.0.0+1 more2023-05-26
CVE-2023-31227 [HIGH] CWE-306 CVE-2023-31227: The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of th The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality.
nvd
CVE-2023-44104P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44104 [HIGH] CWE-669 CVE-2023-44104: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44100P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-10-11
CVE-2023-44100 [HIGH] CWE-669 CVE-2023-44100: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41301P3HIGHCVSS 7.5v2.0.0v2.0.1+2 more2023-09-25
CVE-2023-41301 [HIGH] CWE-269 CVE-2023-41301: Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerab Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-44101P3HIGHCVSS 7.5v2.0.0v2.1.0+2 more2023-10-11
CVE-2023-44101 [HIGH] CWE-668 CVE-2023-44101: The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successfu The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-44093P3HIGHCVSS 7.5v2.0v2.0.1+4 more2023-10-11
CVE-2023-44093 [HIGH] CWE-200 CVE-2023-44093: Vulnerability of package names' public keys not being verified in the security module.Successful exp Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
Huawei Harmonyos vulnerabilities | cvebase