Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 17 of 56
CVE-2023-26547P3HIGHCVSS 7.8v2.0v2.0.1+5 more2023-03-27
CVE-2023-26547 [HIGH] CWE-502 CVE-2023-26547: The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exp
The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2021-22416P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22416 [HIGH] CVE-2021-22416: A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
nvd
CVE-2021-22420P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22420 [HIGH] CWE-668 CVE-2021-22420: A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
nvd
CVE-2021-40027P3HIGHCVSS 7.5fixed in 2.0v2.0.0+3 more2022-01-10
CVE-2021-40027 [HIGH] CWE-476 CVE-2021-40027: The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of
The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-34742P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34742 [HIGH] CWE-125 CVE-2022-34742: The system module has a read/write vulnerability. Successful exploitation of this vulnerability may
The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40065P3HIGHCVSS 7.5v2.02022-04-11
CVE-2021-40065 [HIGH] CVE-2021-40065: The communication module has a service logic error vulnerability.Successful exploitation of this vul
The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-37037P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37037 [HIGH] CVE-2021-37037: There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of thi
There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2021-39970P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39970 [HIGH] CWE-22 CVE-2021-39970: HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerab
HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission.
nvd
CVE-2021-37009P3HIGHCVSS 7.5v2.02021-11-23
CVE-2021-37009 [HIGH] CVE-2021-37009: There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerab
There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
nvd
CVE-2021-40022P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40022 [HIGH] CVE-2021-40022: The weaver module has a vulnerability in parameter type verification,Successful exploitation of this
The weaver module has a vulnerability in parameter type verification,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-37075P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37075 [HIGH] CVE-2021-37075: There is a Credentials Management Errors vulnerability in Huawei Smartphone.Successful exploitation
There is a Credentials Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected.
nvd
CVE-2021-40021P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40021 [HIGH] CWE-787 CVE-2021-40021: The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulne
The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40025P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40025 [HIGH] CWE-665 CVE-2021-40025: The eID module has a vulnerability that causes the memory to be used without being initialized,Succe
The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40018P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40018 [HIGH] CWE-476 CVE-2021-40018: The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerabi
The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-39972P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39972 [HIGH] CWE-200 CVE-2021-39972: MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successf
MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
nvd
CVE-2021-37060P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37060 [HIGH] CWE-20 CVE-2021-37060: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to SAMGR Heap Address Leakage.
nvd
CVE-2021-37096P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37096 [HIGH] CWE-20 CVE-2021-37096: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.
nvd
CVE-2021-40004P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40004 [HIGH] CWE-276 CVE-2021-40004: The cellular module has a vulnerability in permission management. Successful exploitation of this vu
The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-29792P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29792 [HIGH] CVE-2022-29792: The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnera
The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40061P3HIGHCVSS 7.5v2.02022-03-10
CVE-2021-40061 [HIGH] CWE-843 CVE-2021-40061: There is a vulnerability of accessing resources using an incompatible type (type confusion) in the B
There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
nvd