Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 2 of 56
CVE-2023-52370P3CRITICALCVSS 9.8v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52370 [CRITICAL] CWE-120 CVE-2023-52370: Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vuln
Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.
nvd
CVE-2022-37003P3CRITICALCVSS 9.8v2.02022-08-10
CVE-2022-37003 [CRITICAL] CWE-276 CVE-2022-37003: The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnera
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
nvd
CVE-2023-41296P3CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-41296 [CRITICAL] CWE-862 CVE-2023-41296: Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnera
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
nvd
CVE-2023-52953P3CRITICALCVSS 9.1v2.0.0v2.1.0+1 more2025-01-08
CVE-2023-52953 [CRITICAL] CWE-22 CVE-2023-52953: Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vuln
Path traversal vulnerability in the Medialibrary module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2021-37022P3CRITICALCVSS 9.8v2.02021-11-23
CVE-2021-37022 [CRITICAL] CWE-787 CVE-2021-37022: There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of
There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.
nvd
CVE-2021-39990P3CRITICALCVSS 9.8fixed in 2.0v2.02022-01-03
CVE-2021-39990 [CRITICAL] CWE-787 CVE-2021-39990: The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of th
The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.
nvd
CVE-2022-44558P3CRITICALCVSS 9.8v2.0v2.12022-11-09
CVE-2022-44558 [CRITICAL] CWE-502 CVE-2022-44558: The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitatio
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2022-44562P3CRITICALCVSS 9.8v2.0v2.1+1 more2022-11-09
CVE-2022-44562 [CRITICAL] CWE-502 CVE-2022-44562: The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2022-44559P3CRITICALCVSS 9.8v2.0v2.1+1 more2022-11-09
CVE-2022-44559 [CRITICAL] CWE-502 CVE-2022-44559: The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitatio
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2024-32991P3CRITICALCVSS 9.8v2.0.0v2.1.0+4 more2024-05-14
CVE-2024-32991 [CRITICAL] CWE-16 CVE-2024-32991: Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation o
Permission verification vulnerability in the wpa_supplicant module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2021-39982P3CRITICALCVSS 9.1v2.02022-01-03
CVE-2021-39982 [CRITICAL] CWE-269 CVE-2021-39982: Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.
nvd
CVE-2022-38986P3CRITICALCVSS 9.1v2.02022-10-14
CVE-2022-38986 [CRITICAL] CWE-787 CVE-2022-38986: The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel spa
The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.
nvd
CVE-2024-45443P3CRITICALCVSS 9.1v2.0.0v2.1.0+4 more2024-09-04
CVE-2024-45443 [CRITICAL] CWE-22 CVE-2024-45443: Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnera
Directory traversal vulnerability in the cust module
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2021-46839P3CRITICALCVSS 9.1v2.02022-10-14
CVE-2021-46839 [CRITICAL] CWE-125 CVE-2021-46839: The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitatio
The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
nvd
CVE-2023-39407P3CRITICALCVSS 9.1v2.0.02023-09-25
CVE-2023-39407 [CRITICAL] CWE-22 CVE-2023-39407: The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability ma
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
nvd
CVE-2023-39385P3CRITICALCVSS 9.1v2.0.0v2.1.0+1 more2023-08-13
CVE-2023-39385 [CRITICAL] CWE-16 CVE-2023-39385: Vulnerability of configuration defects in the media module of certain products.. Successful exploita
Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.
nvd
CVE-2024-30414P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-04-07
CVE-2024-30414 [HIGH] CWE-78 CVE-2024-30414: Command injection vulnerability in the AccountManager module. Impact: Successful exploitation of thi
Command injection vulnerability in the AccountManager module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-46316P3CRITICALCVSS 9.8fixed in 2.1v2.1+1 more2022-12-20
CVE-2022-46316 [CRITICAL] CWE-287 CVE-2022-46316: A thread security vulnerability exists in the authentication process. Successful exploitation of thi
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
nvd
CVE-2022-48513P3CRITICALCVSS 9.8v2.0.0v2.0.1+2 more2023-07-06
CVE-2022-48513 [CRITICAL] CWE-290 CVE-2022-48513: Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation
Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.
nvd
CVE-2022-46327P3CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46327 [CRITICAL] CWE-269 CVE-2022-46327: Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
nvd