cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 17 of 56
CVE-2023-26547P3HIGHCVSS 7.8v2.0v2.0.1+5 more2023-03-27
CVE-2023-26547 [HIGH] CWE-502 CVE-2023-26547: The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exp The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2021-22416P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22416 [HIGH] CVE-2021-22416: A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
nvd
CVE-2021-22420P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22420 [HIGH] CWE-668 CVE-2021-22420: A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
nvd
CVE-2021-40027P3HIGHCVSS 7.5fixed in 2.0v2.0.0+3 more2022-01-10
CVE-2021-40027 [HIGH] CWE-476 CVE-2021-40027: The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-34742P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34742 [HIGH] CWE-125 CVE-2022-34742: The system module has a read/write vulnerability. Successful exploitation of this vulnerability may The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40065P3HIGHCVSS 7.5v2.02022-04-11
CVE-2021-40065 [HIGH] CVE-2021-40065: The communication module has a service logic error vulnerability.Successful exploitation of this vul The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-37037P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37037 [HIGH] CVE-2021-37037: There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of thi There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2021-39970P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39970 [HIGH] CWE-22 CVE-2021-39970: HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerab HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission.
nvd
CVE-2021-37009P3HIGHCVSS 7.5v2.02021-11-23
CVE-2021-37009 [HIGH] CVE-2021-37009: There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerab There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
nvd
CVE-2021-40022P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40022 [HIGH] CVE-2021-40022: The weaver module has a vulnerability in parameter type verification,Successful exploitation of this The weaver module has a vulnerability in parameter type verification,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-37075P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37075 [HIGH] CVE-2021-37075: There is a Credentials Management Errors vulnerability in Huawei Smartphone.Successful exploitation There is a Credentials Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected.
nvd
CVE-2021-40021P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40021 [HIGH] CWE-787 CVE-2021-40021: The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulne The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40025P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40025 [HIGH] CWE-665 CVE-2021-40025: The eID module has a vulnerability that causes the memory to be used without being initialized,Succe The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40018P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40018 [HIGH] CWE-476 CVE-2021-40018: The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerabi The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-39972P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39972 [HIGH] CWE-200 CVE-2021-39972: MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successf MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
nvd
CVE-2021-37060P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37060 [HIGH] CWE-20 CVE-2021-37060: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to SAMGR Heap Address Leakage.
nvd
CVE-2021-37096P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37096 [HIGH] CWE-20 CVE-2021-37096: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.
nvd
CVE-2021-40004P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40004 [HIGH] CWE-276 CVE-2021-40004: The cellular module has a vulnerability in permission management. Successful exploitation of this vu The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-29792P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29792 [HIGH] CVE-2022-29792: The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnera The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40061P3HIGHCVSS 7.5v2.02022-03-10
CVE-2021-40061 [HIGH] CWE-843 CVE-2021-40061: There is a vulnerability of accessing resources using an incompatible type (type confusion) in the B There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
nvd
Huawei Harmonyos vulnerabilities | cvebase