cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 16 of 56
CVE-2024-58110P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58110 [HIGH] CWE-120 CVE-2024-58110: Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerabil Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58109P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58109 [HIGH] CWE-120 CVE-2024-58109: Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerabil Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-31175P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2025-04-07
CVE-2025-31175 [HIGH] CWE-502 CVE-2025-31175: Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of thi Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2024-54119P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54119 [HIGH] CWE-200 CVE-2024-54119: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54104P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54104 [HIGH] CWE-264 CVE-2024-54104: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56448P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2025-01-08
CVE-2024-56448 [HIGH] CWE-94 CVE-2024-56448: Vulnerability of improper access control in the home screen widget module Impact: Successful exploit Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51523P3HIGHCVSS 7.5v5.0.02024-11-05
CVE-2024-51523 [HIGH] CWE-840 CVE-2024-51523: Information management vulnerability in the Gallery module Impact: Successful exploitation of this v Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56443P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-56443 [HIGH] CWE-200 CVE-2024-56443: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54121P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-54121 [HIGH] CWE-20 CVE-2024-54121: Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerab Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2024-57960P3HIGHCVSS 7.5v3.0.0v3.1.0+3 more2025-02-06
CVE-2024-57960 [HIGH] CWE-20 CVE-2024-57960: Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitati Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54112P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54112 [HIGH] CWE-1021 CVE-2024-54112: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56435P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-56435 [HIGH] CWE-1021 CVE-2024-56435: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56436P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-56436 [HIGH] CWE-1021 CVE-2024-56436: Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation o Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-54610P3HIGHCVSS 7.5v5.0.1v5.1.02025-08-06
CVE-2025-54610 [HIGH] CWE-129 CVE-2025-54610: Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of thi Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54609P3HIGHCVSS 7.5v5.0.1v5.1.02025-08-06
CVE-2025-54609 [HIGH] CWE-125 CVE-2025-54609: Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of thi Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-54114P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54114 [HIGH] CWE-754 CVE-2024-54114: Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-56434P3HIGHCVSS 7.5v4.0.0v4.2.02025-01-08
CVE-2024-56434 [HIGH] CWE-416 CVE-2024-56434: UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerabi UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause service exceptions of the device.
nvd
CVE-2021-37016P3CRITICALCVSS 9.1v2.02021-11-23
CVE-2021-37016 [CRITICAL] CWE-125 CVE-2021-37016: There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vul There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.
nvd
CVE-2025-46590P3MEDIUMCVSS 6.5v5.0.02025-05-06
CVE-2025-46590 [MEDIUM] CWE-287 CVE-2025-46590: Bypass vulnerability in the network search instruction authentication module Impact: Successful expl Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.
nvd
CVE-2021-22376P3HIGHCVSS 8.4v2.02021-06-30
CVE-2021-22376 [HIGH] CWE-269 CVE-2021-22376: A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.
nvd
Huawei Harmonyos vulnerabilities | cvebase