Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 23 of 56
CVE-2024-32992P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-05-14
CVE-2024-32992 [HIGH] CWE-20 CVE-2024-32992: Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of th
Insufficient verification vulnerability in the baseband module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-37006P3HIGHCVSS 7.5v2.0v2.12022-08-10
CVE-2022-37006 [HIGH] CWE-276 CVE-2022-37006: Permission control vulnerability in the network module. Successful exploitation of this vulnerabilit
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
nvd
CVE-2023-46758P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46758 [HIGH] CWE-269 CVE-2023-46758: Permission management vulnerability in the multi-screen interaction module. Successful exploitation
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
nvd
CVE-2021-40030P3HIGHCVSS 7.5v2.02022-08-10
CVE-2021-40030 [HIGH] CVE-2021-40030: The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affe
The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-46322P3HIGHCVSS 7.5fixed in 2.0v2.02022-12-20
CVE-2022-46322 [HIGH] CWE-787 CVE-2022-46322: Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnera
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
nvd
CVE-2022-44555P3HIGHCVSS 7.5v2.0v2.1+1 more2022-11-09
CVE-2022-44555 [HIGH] CWE-294 CVE-2022-44555: The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
nvd
CVE-2023-34163P3HIGHCVSS 7.5v3.1.0v3.0.0+3 more2023-06-19
CVE-2023-34163 [HIGH] CVE-2023-34163: Permission control vulnerability in the window management module.Successful exploitation of this vul
Permission control vulnerability in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-34162P3HIGHCVSS 7.5v3.1.0v3.0.02023-06-19
CVE-2023-34162 [HIGH] CVE-2023-34162: Version update determination vulnerability in the user profile module.Successful exploitation of thi
Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may cause repeated HMS Core updates and cause services to fail.
nvd
CVE-2022-41586P3HIGHCVSS 7.5v2.0v2.12022-10-14
CVE-2022-41586 [HIGH] CWE-130 CVE-2022-41586: The communication framework module has a vulnerability of not truncating data properly.Successful ex
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-38981P3HIGHCVSS 7.5v2.0v2.12022-10-14
CVE-2022-38981 [HIGH] CWE-125 CVE-2022-38981: The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnera
The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.
nvd
CVE-2023-26549P3HIGHCVSS 7.5v2.0v2.0.1+5 more2023-03-27
CVE-2023-26549 [HIGH] CWE-233 CVE-2023-26549: The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successf
The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2024-32989P3HIGHCVSS 7.5v3.1.0v4.0.0+1 more2024-05-14
CVE-2024-32989 [HIGH] CWE-20 CVE-2024-32989: Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful explo
Insufficient verification vulnerability in the system sharing pop-up module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-34161P3HIGHCVSS 7.5v3.1.0v3.0.0+3 more2023-06-19
CVE-2023-34161 [HIGH] CWE-863 CVE-2023-34161: nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of t
nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2022-48516P3HIGHCVSS 7.5v2.0.0v2.0.12023-07-06
CVE-2022-48516 [HIGH] CWE-200 CVE-2022-48516: Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Succe
Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality.
nvd
CVE-2022-41599P3HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-41599 [HIGH] CVE-2022-41599: The system service has a vulnerability that causes incorrect return values. Successful exploitation
The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-46328P3HIGHCVSS 7.5fixed in 2.1v2.0+1 more2022-12-20
CVE-2022-46328 [HIGH] CWE-20 CVE-2022-46328: Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerabil
Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-44095P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-10-11
CVE-2023-44095 [HIGH] CWE-416 CVE-2023-44095: Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vuln
Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash.
nvd
CVE-2022-46310P3HIGHCVSS 7.5fixed in 3.0.0v3.0.02022-12-20
CVE-2022-46310 [HIGH] CWE-200 CVE-2022-46310: The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this
The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-1695P3HIGHCVSS 7.5v2.0.0v2.0.1+2 more2023-07-06
CVE-2023-1695 [HIGH] CWE-755 CVE-2023-1695: Vulnerability of failures to capture exceptions in the communication framework. Successful exploitat
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-1691P3HIGHCVSS 7.5v2.0.0v2.0.1+2 more2023-07-06
CVE-2023-1691 [HIGH] CWE-248 CVE-2023-1691: Vulnerability of failures to capture exceptions in the communication framework. Successful exploitat
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd