cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 20 of 56
CVE-2023-44117P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-44117 [HIGH] CWE-290 CVE-2023-44117: Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitat Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-4566P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-4566 [HIGH] CWE-290 CVE-2023-4566: Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitat Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52107P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52107 [HIGH] CWE-269 CVE-2023-52107: Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-27896P3HIGHCVSS 7.5v3.0.02024-04-08
CVE-2024-27896 [HIGH] CWE-20 CVE-2024-27896: Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerab Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.
nvd
CVE-2023-52360P3HIGHCVSS 7.5v2.0.0v2.1.0+1 more2024-02-18
CVE-2023-52360 [HIGH] CWE-511 CVE-2023-52360: Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect servi Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2021-22484P3HIGHCVSS 7.5v2.0.0v2.02024-12-28
CVE-2021-22484 [HIGH] CWE-20 CVE-2021-22484: Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful exploitation of this vulnerability may cause a server out of memory (OOM).
nvd
CVE-2023-52114P3HIGHCVSS 7.5v2.0.0v3.0.0+2 more2024-01-16
CVE-2023-52114 [HIGH] CWE-269 CVE-2023-52114: Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulne Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2024-57954P3HIGHCVSS 7.5v5.0.02025-02-06
CVE-2024-57954 [HIGH] CWE-285 CVE-2024-57954: Permission verification vulnerability in the media library module Impact: Successful exploitation of Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-12602P3HIGHCVSS 7.5v5.0.02025-02-06
CVE-2024-12602 [HIGH] CWE-300 CVE-2024-12602: Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of th Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-46320P3CRITICALCVSS 9.8fixed in 2.0v2.0+2 more2022-12-20
CVE-2022-46320 [CRITICAL] CWE-125 CVE-2022-46320: The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerabi The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
nvd
CVE-2025-54630P3HIGHCVSS 7.5v4.3.0v5.0.12025-08-06
CVE-2025-54630 [HIGH] CWE-122 CVE-2025-54630: :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploi :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52375P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52375 [HIGH] CWE-284 CVE-2023-52375: Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-47294P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-09-27
CVE-2024-47294 [HIGH] CWE-16 CVE-2024-47294: Access permission verification vulnerability in the input method framework module Impact: Successful Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58115P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58115 [HIGH] CWE-121 CVE-2024-58115: Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful ex Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58116P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58116 [HIGH] CWE-121 CVE-2024-58116: Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful ex Buffer overflow vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-56440P3HIGHCVSS 7.5v3.0.0v3.1.0+2 more2025-01-08
CVE-2024-56440 [HIGH] CWE-264 CVE-2024-56440: Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-52109P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-52109 [HIGH] CWE-345 CVE-2023-52109: Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitat Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52954P3HIGHCVSS 7.5v2.0.0v2.1.0+2 more2025-01-08
CVE-2023-52954 [HIGH] CWE-701 CVE-2023-52954: Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation o Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-37051P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-08
CVE-2021-37051 [CRITICAL] CWE-125 CVE-2021-37051: There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vu There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2021-37134P3HIGHCVSS 8.1fixed in 2.0v2.02022-01-03
CVE-2021-37134 [HIGH] CWE-362 CVE-2021-37134: Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerab Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.
nvd
Huawei Harmonyos vulnerabilities | cvebase