cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 25 of 56
CVE-2026-34856P3HIGHCVSS 7.5v6.0.02026-04-13
CVE-2026-34856 [HIGH] CWE-362 CVE-2026-34856: UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34851P3HIGHCVSS 7.5v5.1.0v6.0.02026-04-13
CVE-2026-34851 [HIGH] CWE-362 CVE-2026-34851: Race condition vulnerability in the event notification module. Impact: Successful exploitation of th Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52553P3HIGHCVSS 7.4v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52553 [HIGH] CWE-362 CVE-2023-52553: Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerabil Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-29793P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29793 [HIGH] CVE-2022-29793: There is a configuration defect in the activation lock of mobile phones.Successful exploitation of t There is a configuration defect in the activation lock of mobile phones.Successful exploitation of this vulnerability may affect application availability.
nvd
CVE-2021-40035P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40035 [HIGH] CWE-120 CVE-2021-40035: There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file m There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file management module in smartphones. Successful exploitation of this vulnerability may affect function stability.
nvd
CVE-2021-40029P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40029 [HIGH] CWE-120 CVE-2021-40029: There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file m There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file management module in smartphones. Successful exploitation of this vulnerability may affect function stability.
nvd
CVE-2021-40011P3HIGHCVSS 7.5v2.02022-01-10
CVE-2021-40011 [HIGH] CWE-400 CVE-2021-40011: There is an uncontrolled resource consumption vulnerability in the display module. Successful exploi There is an uncontrolled resource consumption vulnerability in the display module. Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2021-37097P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37097 [HIGH] CWE-94 CVE-2021-37097: There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnera There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.
nvd
CVE-2021-46787P3HIGHCVSS 7.5v2.02022-05-13
CVE-2021-46787 [HIGH] CVE-2021-46787: The AMS module has a vulnerability of improper permission control.Successful exploitation of this vu The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.
nvd
CVE-2021-39974P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39974 [HIGH] CWE-125 CVE-2021-39974: There is an Out-of-bounds read in Smartphones.Successful exploitation of this vulnerability may affe There is an Out-of-bounds read in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37052P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37052 [HIGH] CWE-755 CVE-2021-37052: There is an Exception log vulnerability in Huawei Smartphone.Successful exploitation of this vulnera There is an Exception log vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause address information leakage.
nvd
CVE-2022-34735P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34735 [HIGH] CWE-476 CVE-2022-34735: The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
nvd
CVE-2022-34736P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34736 [HIGH] CWE-476 CVE-2022-34736: The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
nvd
CVE-2022-34743P3HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34743 [HIGH] CWE-125 CVE-2022-34743: The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2022-29790P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29790 [HIGH] CVE-2022-29790: The graphics acceleration service has a vulnerability in multi-thread access to the database.Success The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.
nvd
CVE-2022-29795P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29795 [HIGH] CWE-476 CVE-2022-29795: The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
nvd
CVE-2022-31753P3HIGHCVSS 7.5v2.02022-06-13
CVE-2022-31753 [HIGH] CWE-134 CVE-2022-31753: The voice wakeup module has a vulnerability of using externally-controlled format strings. Successfu The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2022-47975P3HIGHCVSS 7.5fixed in 2.0v2.0+1 more2023-01-06
CVE-2022-47975 [HIGH] CWE-415 CVE-2022-47975: The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2022-46315P3HIGHCVSS 7.5fixed in 2.1v2.1+3 more2022-12-20
CVE-2022-46315 [HIGH] CWE-400 CVE-2022-46315: The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnera The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2023-41307P3HIGHCVSS 7.5v2.0.0v2.1.0+1 more2023-09-27
CVE-2023-41307 [HIGH] CWE-787 CVE-2023-41307: Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerabili Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.
nvd
Huawei Harmonyos vulnerabilities | cvebase