cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 21 of 56
CVE-2022-41576P3HIGHCVSS 7.8v2.02022-10-14
CVE-2022-41576 [HIGH] CWE-94 CVE-2022-41576: The rphone module has a script that can be maliciously modified.Successful exploitation of this vuln The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.
nvd
CVE-2021-40014P3HIGHCVSS 7.5fixed in 2.0v2.0.0+3 more2022-01-10
CVE-2021-40014 [HIGH] CWE-787 CVE-2021-40014: The bone voice ID trusted application (TA) has a heap overflow vulnerability. Successful exploitatio The bone voice ID trusted application (TA) has a heap overflow vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-22458P3HIGHCVSS 7.8v2.02021-10-28
CVE-2021-22458 [HIGH] CWE-125 CVE-2021-22458: A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.
nvd
CVE-2022-31762P3HIGHCVSS 7.8v2.02022-06-13
CVE-2022-31762 [HIGH] CWE-20 CVE-2022-31762: The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerabilit The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2021-22418P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22418 [HIGH] CWE-190 CVE-2021-22418: A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
nvd
CVE-2021-22422P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22422 [HIGH] CWE-190 CVE-2021-22422: A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
nvd
CVE-2021-22423P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22423 [HIGH] CWE-787 CVE-2021-22423: A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit th A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.
nvd
CVE-2021-22451P3HIGHCVSS 7.8v2.02021-10-28
CVE-2021-22451 [HIGH] CWE-190 CVE-2021-22451: A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
nvd
CVE-2021-22470P3HIGHCVSS 7.8v2.02021-10-28
CVE-2021-22470 [HIGH] CVE-2021-22470: A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit th A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.
nvd
CVE-2021-22421P3HIGHCVSS 7.8v2.02021-08-03
CVE-2021-22421 [HIGH] CWE-269 CVE-2021-22421: A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.
nvd
CVE-2021-37000P3HIGHCVSS 7.8v2.0.0v2.02024-12-28
CVE-2021-37000 [HIGH] CWE-255 CVE-2021-37000: Some Huawei wearables have a permission management vulnerability. Some Huawei wearables have a permission management vulnerability.
nvd
CVE-2021-40032P3HIGHCVSS 7.5fixed in 2.0v2.0.0+3 more2022-01-10
CVE-2021-40032 [HIGH] CVE-2021-40032: The bone voice ID TA has a vulnerability in information management,Successful exploitation of this v The bone voice ID TA has a vulnerability in information management,Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2025-48903P3HIGHCVSS 7.8v5.0.02025-06-06
CVE-2025-48903 [HIGH] CWE-264 CVE-2025-48903: Permission bypass vulnerability in the media library module Impact: Successful exploitation of this Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-40064P3HIGHCVSS 7.5v2.02022-03-10
CVE-2021-40064 [HIGH] CWE-787 CVE-2021-40064: There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stability.
nvd
CVE-2021-40049P3HIGHCVSS 7.5v2.02022-03-10
CVE-2021-40049 [HIGH] CWE-276 CVE-2021-40049: There is a permission control vulnerability in the PMS module. Successful exploitation of this vulne There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
nvd
CVE-2022-39001P3HIGHCVSS 7.5v2.02022-09-16
CVE-2022-39001 [HIGH] CWE-22 CVE-2022-39001: The number identification module has a path traversal vulnerability. Successful exploitation of this The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.
nvd
CVE-2021-46741P3HIGHCVSS 7.5v2.02022-07-12
CVE-2021-46741 [HIGH] CVE-2021-46741: The basic framework and setting module have defects, which were introduced during the design. Succes The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of this vulnerability may affect system integrity.
nvd
CVE-2021-37026P3HIGHCVSS 7.5v2.02021-11-23
CVE-2021-37026 [HIGH] CWE-20 CVE-2021-37026: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
nvd
CVE-2021-37110P3HIGHCVSS 7.5fixed in 2.02022-01-03
CVE-2021-37110 [HIGH] CVE-2021-37110: There is a Timing design defects in Smartphone.Successful exploitation of this vulnerability may aff There is a Timing design defects in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-39966P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39966 [HIGH] CWE-909 CVE-2021-39966: There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulner There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
nvd