Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 20 of 56
CVE-2023-44117P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-44117 [HIGH] CWE-290 CVE-2023-44117: Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitat
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-4566P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-4566 [HIGH] CWE-290 CVE-2023-4566: Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitat
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52107P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52107 [HIGH] CWE-269 CVE-2023-52107: Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation
Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-27896P3HIGHCVSS 7.5v3.0.02024-04-08
CVE-2024-27896 [HIGH] CWE-20 CVE-2024-27896: Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerab
Input verification vulnerability in the log module.
Impact: Successful exploitation of this vulnerability can affect integrity.
nvd
CVE-2023-52360P3HIGHCVSS 7.5v2.0.0v2.1.0+1 more2024-02-18
CVE-2023-52360 [HIGH] CWE-511 CVE-2023-52360: Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect servi
Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2021-22484P3HIGHCVSS 7.5v2.0.0v2.02024-12-28
CVE-2021-22484 [HIGH] CWE-20 CVE-2021-22484: Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data.
Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data.
Successful exploitation of this vulnerability may cause a server out of memory (OOM).
nvd
CVE-2023-52114P3HIGHCVSS 7.5v2.0.0v3.0.0+2 more2024-01-16
CVE-2023-52114 [HIGH] CWE-269 CVE-2023-52114: Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulne
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2024-57954P3HIGHCVSS 7.5v5.0.02025-02-06
CVE-2024-57954 [HIGH] CWE-285 CVE-2024-57954: Permission verification vulnerability in the media library module Impact: Successful exploitation of
Permission verification vulnerability in the media library module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-12602P3HIGHCVSS 7.5v5.0.02025-02-06
CVE-2024-12602 [HIGH] CWE-300 CVE-2024-12602: Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of th
Identity verification vulnerability in the ParamWatcher module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-46320P3CRITICALCVSS 9.8fixed in 2.0v2.0+2 more2022-12-20
CVE-2022-46320 [CRITICAL] CWE-125 CVE-2022-46320: The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerabi
The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
nvd
CVE-2025-54630P3HIGHCVSS 7.5v4.3.0v5.0.12025-08-06
CVE-2025-54630 [HIGH] CWE-122 CVE-2025-54630: :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploi
:Vulnerability of insufficient data length verification in the DFA module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52375P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52375 [HIGH] CWE-284 CVE-2023-52375: Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this
Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-47294P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-09-27
CVE-2024-47294 [HIGH] CWE-16 CVE-2024-47294: Access permission verification vulnerability in the input method framework module Impact: Successful
Access permission verification vulnerability in the input method framework module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58115P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58115 [HIGH] CWE-121 CVE-2024-58115: Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful ex
Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58116P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58116 [HIGH] CWE-121 CVE-2024-58116: Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful ex
Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-56440P3HIGHCVSS 7.5v3.0.0v3.1.0+2 more2025-01-08
CVE-2024-56440 [HIGH] CWE-264 CVE-2024-56440: Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this
Permission control vulnerability in the Connectivity module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-52109P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-52109 [HIGH] CWE-345 CVE-2023-52109: Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitat
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52954P3HIGHCVSS 7.5v2.0.0v2.1.0+2 more2025-01-08
CVE-2023-52954 [HIGH] CWE-701 CVE-2023-52954: Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation o
Vulnerability of improper permission control in the Gallery module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-37051P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-08
CVE-2021-37051 [CRITICAL] CWE-125 CVE-2021-37051: There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vu
There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2021-37134P3HIGHCVSS 8.1fixed in 2.0v2.02022-01-03
CVE-2021-37134 [HIGH] CWE-362 CVE-2021-37134: Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerab
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.
nvd