Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 18 of 56
CVE-2021-37048P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37048 [HIGH] CWE-20 CVE-2021-37048: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to fake visitors to control PC,play a video,etc.
nvd
CVE-2023-41309P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-27
CVE-2023-41309 [HIGH] CWE-269 CVE-2023-41309: Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of t
Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-39010P3HIGHCVSS 7.5v2.02022-09-16
CVE-2022-39010 [HIGH] CVE-2022-39010: The HwChrService module has a vulnerability in permission control. Successful exploitation of this v
The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information.
nvd
CVE-2023-46769P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46769 [HIGH] CWE-416 CVE-2023-46769: Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerabili
Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-41308P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-09-27
CVE-2023-41308 [HIGH] CWE-532 CVE-2023-41308: Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affe
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-0116P3HIGHCVSS 7.5v3.1.0v3.0.0+3 more2023-05-26
CVE-2023-0116 [HIGH] CWE-306 CVE-2023-0116: The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitati
The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46852P3HIGHCVSS 7.5v2.02022-11-09
CVE-2021-46852 [HIGH] CWE-306 CVE-2021-46852: The memory management module has the logic bypass vulnerability. Successful exploitation of this vul
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-37241P3HIGHCVSS 7.5v3.0.0v3.1.02023-07-06
CVE-2023-37241 [HIGH] CWE-20 CVE-2023-37241: Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may c
Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2022-48517P3HIGHCVSS 7.5v2.0.0v2.0.1+1 more2023-07-06
CVE-2022-48517 [HIGH] CWE-701 CVE-2022-48517: Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vu
Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-44556P3HIGHCVSS 7.5v2.0v3.0.0+2 more2022-11-08
CVE-2022-44556 [HIGH] CWE-20 CVE-2022-44556: Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability m
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-46762P3HIGHCVSS 7.5fixed in 2.0v2.02023-01-06
CVE-2022-46762 [HIGH] CWE-693 CVE-2022-46762: The memory management module has a logic bypass vulnerability.Successful exploitation of this vulner
The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38998P3HIGHCVSS 7.5v2.02022-10-14
CVE-2022-38998 [HIGH] CWE-125 CVE-2022-38998: The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Succes
The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
nvd
CVE-2022-38984P3HIGHCVSS 7.5v2.02022-10-14
CVE-2022-38984 [HIGH] CWE-125 CVE-2022-38984: The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Succes
The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
nvd
CVE-2022-38985P3HIGHCVSS 7.5v2.02022-10-14
CVE-2022-38985 [HIGH] CWE-20 CVE-2022-38985: The facial recognition module has a vulnerability in input validation.Successful exploitation of thi
The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48347P3HIGHCVSS 7.5v3.0.02023-03-27
CVE-2022-48347 [HIGH] CWE-200 CVE-2022-48347: The MediaProvider module has a vulnerability in permission verification. Successful exploitation of
The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2021-46868P3HIGHCVSS 7.5fixed in 2.0v2.02023-01-06
CVE-2021-46868 [HIGH] CWE-125 CVE-2021-46868: The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerabil
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
nvd
CVE-2021-46867P3HIGHCVSS 7.5fixed in 2.0v2.02023-01-06
CVE-2021-46867 [HIGH] CWE-125 CVE-2021-46867: The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerabil
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
nvd
CVE-2022-46321P3HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-46321 [HIGH] CVE-2022-46321: The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vul
The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-52110P3HIGHCVSS 7.5v4.0.02024-01-16
CVE-2023-52110 [HIGH] CWE-787 CVE-2023-52110: The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerab
The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-39390P3HIGHCVSS 7.5v3.0.0v3.1.02023-08-13
CVE-2023-39390 [HIGH] CWE-20 CVE-2023-39390: Vulnerability of input parameter verification in certain APIs in the window management module. Succe
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
nvd