Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 19 of 56
CVE-2023-39404P3HIGHCVSS 7.5v3.0.0v3.1.02023-08-13
CVE-2023-39404 [HIGH] CWE-20 CVE-2023-39404: Vulnerability of input parameter verification in certain APIs in the window management module. Succe
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2023-39406P3HIGHCVSS 7.5v3.0.02023-08-13
CVE-2023-39406 [HIGH] CWE-264 CVE-2023-39406: Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerabi
Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
nvd
CVE-2023-1694P3HIGHCVSS 7.5fixed in 3.1.0v3.1.02023-05-20
CVE-2023-1694 [HIGH] CWE-269 CVE-2023-1694: The Settings module has the file privilege escalation vulnerability.Successful exploitation of this
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-1692P3HIGHCVSS 7.5v2.0v2.0.1+5 more2023-05-20
CVE-2023-1692 [HIGH] CWE-732 CVE-2023-1692: The window management module lacks permission verification.Successful exploitation of this vulnerabi
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-1693P3HIGHCVSS 7.5fixed in 3.1.0v3.1.02023-05-20
CVE-2023-1693 [HIGH] CWE-269 CVE-2023-1693: The Settings module has the file privilege escalation vulnerability.Successful exploitation of this
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48286P3HIGHCVSS 7.5v2.0v2.1+2 more2023-02-09
CVE-2022-48286 [HIGH] CWE-269 CVE-2022-48286: The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitat
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-31226P3HIGHCVSS 7.5v3.1.02023-05-26
CVE-2023-31226 [HIGH] CWE-863 CVE-2023-31226: The SDK for the MediaPlaybackController module has improper permission verification. Successful expl
The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48287P3HIGHCVSS 7.5v2.0v2.1+1 more2023-02-09
CVE-2022-48287 [HIGH] CWE-693 CVE-2022-48287: The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerabilit
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2023-44114P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-10-11
CVE-2023-44114 [HIGH] CWE-125 CVE-2023-44114: Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerabilit
Out-of-bounds array vulnerability in the dataipa module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44103P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-10-11
CVE-2023-44103 [HIGH] CWE-20 CVE-2023-44103: Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerabili
Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52715P3HIGHCVSS 7.5v4.0.02024-04-07
CVE-2023-52715 [HIGH] CWE-732 CVE-2023-52715: The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of
The SystemUI module has a vulnerability in permission management.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-30413P3HIGHCVSS 7.5v3.1.0v4.0.02024-04-07
CVE-2024-30413 [HIGH] CWE-732 CVE-2024-30413: Vulnerability of improper permission control in the window management module. Impact: Successful exp
Vulnerability of improper permission control in the window management module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-39380P3HIGHCVSS 7.5v3.0.0v3.1.02023-08-13
CVE-2023-39380 [HIGH] CWE-264 CVE-2023-39380: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
nvd
CVE-2021-46893P3HIGHCVSS 7.5v2.0v2.0.02023-07-05
CVE-2021-46893 [HIGH] CWE-1284 CVE-2021-46893: Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vul
Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2023-52097P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52097 [HIGH] CWE-200 CVE-2023-52097: Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploit
Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52376P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52376 [HIGH] CWE-212 CVE-2023-52376: Information management vulnerability in the Gallery module.Successful exploitation of this vulnerabi
Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52102P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52102 [HIGH] CWE-116 CVE-2023-52102: Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vu
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52104P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-52104 [HIGH] CVE-2023-52104: Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vu
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44109P3HIGHCVSS 7.5v2.0v2.0.1+5 more2023-10-11
CVE-2023-44109 [HIGH] CWE-74 CVE-2023-44109: Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect s
Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52099P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52099 [HIGH] CWE-284 CVE-2023-52099: Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploi
Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd