cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 15 of 56
CVE-2022-48350P3HIGHCVSS 7.5v3.0.02023-03-27
CVE-2022-48350 [HIGH] CWE-862 CVE-2022-48350: The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48298P3HIGHCVSS 7.5v2.0v3.0.02023-02-09
CVE-2022-48298 [HIGH] CWE-1284 CVE-2022-48298: The geofencing kernel code does not verify the length of the input data. Successful exploitation of The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2022-48606P3HIGHCVSS 7.5v2.0.0v2.0.1+2 more2023-09-27
CVE-2022-48606 [HIGH] CWE-476 CVE-2022-48606: Stability-related vulnerability in the binder background management and control module. Successful e Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52388P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52388 [HIGH] CWE-732 CVE-2023-52388: Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulner Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-52105P3HIGHCVSS 7.5v4.0.02024-01-16
CVE-2023-52105 [HIGH] CWE-269 CVE-2023-52105: The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerab The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-44561P3HIGHCVSS 7.5v2.0v3.0.02022-11-09
CVE-2022-44561 [HIGH] CWE-276 CVE-2022-44561: The preset launcher module has a permission verification vulnerability. Successful exploitation of t The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
nvd
CVE-2024-58107P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58107 [HIGH] CWE-680 CVE-2024-58107: Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerabil Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52549P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52549 [HIGH] CWE-120 CVE-2023-52549: Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of t Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-27897P3HIGHCVSS 7.5v2.0.0v3.0.0+2 more2024-04-08
CVE-2024-27897 [HIGH] CWE-200 CVE-2024-27897: Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnera Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52550P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52550 [HIGH] CWE-120 CVE-2023-52550: Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of t Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52714P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-07
CVE-2023-52714 [HIGH] CWE-657 CVE-2023-52714: Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful ex Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52387P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-02-18
CVE-2023-52387 [HIGH] CWE-664 CVE-2023-52387: Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may af Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41293P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-09-25
CVE-2023-41293 [HIGH] CWE-227 CVE-2023-41293: Data security classification vulnerability in the DDMP module. Successful exploitation of this vulne Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-39383P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39383 [HIGH] CWE-200 CVE-2023-39383: Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploita Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
nvd
CVE-2022-48494P3HIGHCVSS 7.5v3.0.0v2.1.0+2 more2023-06-19
CVE-2022-48494 [HIGH] CWE-287 CVE-2022-48494: Vulnerability of lax app identity verification in the pre-authorization function.Successful exploita Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
nvd
CVE-2022-48496P3HIGHCVSS 7.5v3.1.0v3.0.0+3 more2023-06-19
CVE-2022-48496 [HIGH] CWE-287 CVE-2022-48496: Vulnerability of lax app identity verification in the pre-authorization function.Successful exploita Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.
nvd
CVE-2023-52539P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52539 [HIGH] CWE-285 CVE-2023-52539: Permission verification vulnerability in the Settings module. Impact: Successful exploitation of thi Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52373P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52373 [HIGH] CWE-281 CVE-2023-52373: Vulnerability of permission verification in the content sharing pop-up module.Successful exploitatio Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.
nvd
CVE-2024-58106P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58106 [HIGH] CWE-120 CVE-2024-58106: Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerabil Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58108P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58108 [HIGH] CWE-120 CVE-2024-58108: Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerabil Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
Huawei Harmonyos vulnerabilities | cvebase