cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 24 of 56
CVE-2022-48507P3HIGHCVSS 7.5v2.0.0v2.0.12023-07-06
CVE-2022-48507 [HIGH] CWE-294 CVE-2022-48507: Vulnerability of identity verification being bypassed in the storage module. Successful exploitation Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52386P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-04-08
CVE-2023-52386 [HIGH] CWE-787 CVE-2023-52386: Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulner Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-30416P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-07
CVE-2024-30416 [HIGH] CWE-416 CVE-2024-30416: Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-52372P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52372 [HIGH] CWE-20 CVE-2023-52372: Vulnerability of input parameter verification in the motor module.Successful exploitation of this vu Vulnerability of input parameter verification in the motor module.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52115P3HIGHCVSS 7.5v4.0.02024-01-16
CVE-2023-52115 [HIGH] CWE-416 CVE-2023-52115: The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerab The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.
nvd
CVE-2022-48302P3HIGHCVSS 7.5v2.0v2.1+2 more2023-02-09
CVE-2022-48302 [HIGH] CWE-862 CVE-2022-48302: The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitatio The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-41305P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-27
CVE-2023-41305 [HIGH] CWE-326 CVE-2023-41305: Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS mess Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2024-32990P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-05-14
CVE-2024-32990 [HIGH] CWE-20 CVE-2024-32990: Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploit Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-30418P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-04-07
CVE-2024-30418 [HIGH] CWE-280 CVE-2024-30418: Vulnerability of insufficient permission verification in the app management module. Impact: Successf Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-52116P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52116 [HIGH] CWE-269 CVE-2023-52116: Permission management vulnerability in the multi-screen interaction module. Successful exploitation Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
nvd
CVE-2024-58113P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58113 [HIGH] CWE-399 CVE-2024-58113: Vulnerability of improper resource management in the memory management module Impact: Successful exp Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-46311P3HIGHCVSS 7.5fixed in 2.0v2.02022-12-20
CVE-2022-46311 [HIGH] CWE-416 CVE-2022-46311: The contacts component has a free (undefined) provider vulnerability. Successful exploitation of thi The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2023-39391P3HIGHCVSS 7.5v2.0.0v2.0.1+2 more2023-08-13
CVE-2023-39391 [HIGH] CWE-264 CVE-2023-39391: Vulnerability of system file information leakage in the USB Service module. Successful exploitation Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-46312P3HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-46312 [HIGH] CWE-285 CVE-2022-46312: The application management module has a vulnerability in permission verification. Successful exploit The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.
nvd
CVE-2022-22253P3HIGHCVSS 7.5v2.02022-04-11
CVE-2022-22253 [HIGH] CWE-354 CVE-2022-22253: The DFX module has a vulnerability of improper validation of integrity check values.Successful explo The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability.
nvd
CVE-2021-37069P3HIGHCVSS 7.4fixed in 2.0v2.02021-12-08
CVE-2021-37069 [HIGH] CWE-362 CVE-2021-37069: There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnera There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.
nvd
CVE-2024-56437P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-56437 [HIGH] CWE-20 CVE-2024-56437: Vulnerability of input parameters not being verified in the widget framework module Impact: Successf Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-47293P3HIGHCVSS 7.5v3.0.0v4.0.0+1 more2024-09-27
CVE-2024-47293 [HIGH] CWE-130 CVE-2024-47293: Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vul Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52546P3HIGHCVSS 7.5v3.1.0v4.0.02024-04-08
CVE-2023-52546 [HIGH] CWE-345 CVE-2023-52546: Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful ex Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-54635P3HIGHCVSS 7.5v5.1.02025-08-06
CVE-2025-54635 [HIGH] CWE-416 CVE-2025-54635: Vulnerability of returning released pointers in the distributed notification service. Impact: Succes Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
Huawei Harmonyos vulnerabilities | cvebase