cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 13 of 56
CVE-2023-41298P3HIGHCVSS 7.5v2.0.1v3.0.0+2 more2023-09-25
CVE-2023-41298 [HIGH] CVE-2023-41298: Vulnerability of permission control in the window module. Successful exploitation of this vulnerabil Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2024-54097P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-12-12
CVE-2024-54097 [HIGH] CWE-15 CVE-2024-54097: Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability ma Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.
nvd
CVE-2022-48508P3HIGHCVSS 7.5v2.0.0v2.0.1+1 more2023-07-06
CVE-2022-48508 [HIGH] CWE-264 CVE-2022-48508: Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulne Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2024-57957P3HIGHCVSS 7.5v5.0.02025-02-06
CVE-2024-57957 [HIGH] CWE-657 CVE-2024-57957: Vulnerability of improper log information control in the UI framework module Impact: Successful expl Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-39002P3CRITICALCVSS 9.8v2.02022-09-16
CVE-2022-39002 [CRITICAL] CWE-415 CVE-2022-39002: Double free vulnerability in the storage module. Successful exploitation of this vulnerability will Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.
nvd
CVE-2022-39000P3CRITICALCVSS 9.8v2.0v2.12022-09-16
CVE-2022-39000 [CRITICAL] CVE-2022-39000: The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vul The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
nvd
CVE-2024-54117P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54117 [HIGH] CWE-200 CVE-2024-54117: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54110P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54110 [HIGH] CWE-1021 CVE-2024-54110: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52111P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-52111 [HIGH] CWE-287 CVE-2023-52111: Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2024-56444P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-56444 [HIGH] CWE-264 CVE-2024-56444: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-46851P3CRITICALCVSS 9.8v2.02022-11-09
CVE-2021-46851 [CRITICAL] CWE-284 CVE-2021-46851: The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitatio The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
nvd
CVE-2023-44098P3HIGHCVSS 7.5v2.0.1v2.1.0+3 more2023-11-08
CVE-2023-44098 [HIGH] CWE-200 CVE-2023-44098: Vulnerability of missing encryption in the card management module. Successful exploitation of this v Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37116P3CRITICALCVSS 9.1fixed in 2.0v2.02022-01-03
CVE-2021-37116 [CRITICAL] CWE-20 CVE-2021-37116: PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this v PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.
nvd
CVE-2023-34154P3HIGHCVSS 8.2fixed in 2.0v3.0.0+1 more2023-06-16
CVE-2023-34154 [HIGH] CWE-732 CVE-2023-34154: Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of thi Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources.
nvd
CVE-2021-22425P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22425 [HIGH] CWE-415 CVE-2021-22425: A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulne A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.
nvd
CVE-2024-42038P3HIGHCVSS 7.8v3.0.0v4.0.0+1 more2024-08-08
CVE-2024-42038 [HIGH] CWE-287 CVE-2024-42038: Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
nvd
CVE-2025-68968P3HIGHCVSS 7.8v6.0.02026-01-14
CVE-2025-68968 [HIGH] CWE-415 CVE-2025-68968: Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vu Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.
nvd
CVE-2025-54655P3HIGHCVSS 7.8v5.0.1v5.0.22025-08-06
CVE-2025-54655 [HIGH] CWE-367 CVE-2025-54655: Race condition vulnerability in the virtualization base module. Successful exploitation of this vuln Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module.
nvd
CVE-2021-40051P3HIGHCVSS 7.5v2.02022-03-10
CVE-2021-40051 [HIGH] CVE-2021-40051: There is an unauthorized access vulnerability in system components. Successful exploitation of this There is an unauthorized access vulnerability in system components. Successful exploitation of this vulnerability will affect confidentiality.
nvd
CVE-2021-37091P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37091 [HIGH] CVE-2021-37091: There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful There is a Permissions,Privileges,and Access Controls vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected.
nvd
Huawei Harmonyos vulnerabilities | cvebase