Huawei Harmonyos vulnerabilities

1,076 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,076
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH534MEDIUM365LOW39

Vulnerabilities

Page 25 of 54
CVE-2023-49240HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49240 [HIGH] CWE-601 CVE-2023-49240: Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerabil Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49239HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49239 [HIGH] CWE-863 CVE-2023-49239: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44113HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-44113 [HIGH] CWE-862 CVE-2023-44113: Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) modu Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49245HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49245 [HIGH] CVE-2023-49245: Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulner Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49244HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-49244 [HIGH] CVE-2023-49244: Permission management vulnerability in the multi-user module. Successful exploitation of this vulner Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49242HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49242 [HIGH] CVE-2023-49242: Free broadcast vulnerability in the running management module. Successful exploitation of this vulne Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49243HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49243 [HIGH] CVE-2023-49243: Vulnerability of unauthorized access to email attachments in the email module. Successful exploitati Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44099HIGHCVSS 7.5v2.0.0v2.1.0+2 more2023-12-06
CVE-2023-44099 [HIGH] CWE-754 CVE-2023-44099: Vulnerability of data verification errors in the kernel module. Successful exploitation of this vuln Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.
nvd
CVE-2023-49246HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49246 [HIGH] CWE-863 CVE-2023-49246: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49247HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49247 [HIGH] CWE-295 CVE-2023-49247: Permission verification vulnerability in distributed scenarios. Successful exploitation of this vuln Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49241HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49241 [HIGH] CVE-2023-49241: API permission control vulnerability in the network management module. Successful exploitation of th API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-6273MEDIUMCVSS 5.3v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-6273 [MEDIUM] CWE-276 CVE-2023-6273: Permission management vulnerability in the module for disabling Sound Booster. Successful exploitati Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-49248MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49248 [MEDIUM] CWE-20 CVE-2023-49248: Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulne Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
nvd
CVE-2023-5801CRITICALCVSS 9.1v2.0.0v3.0.0+1 more2023-11-08
CVE-2023-5801 [CRITICAL] CWE-290 CVE-2023-5801: Vulnerability of identity verification being bypassed in the face unlock module. Successful exploita Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2023-46771HIGHCVSS 7.5v2.0.0v3.0.0+1 more2023-11-08
CVE-2023-46771 [HIGH] CWE-269 CVE-2023-46771: Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46761HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46761 [HIGH] CWE-787 CVE-2023-46761: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46767HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46767 [HIGH] CWE-125 CVE-2023-46767: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46758HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46758 [HIGH] CWE-269 CVE-2023-46758: Permission management vulnerability in the multi-screen interaction module. Successful exploitation Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
nvd
CVE-2023-44115HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-44115 [HIGH] CWE-200 CVE-2023-44115: Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46770HIGHCVSS 7.5v2.0.0v3.0.0+1 more2023-11-08
CVE-2023-46770 [HIGH] CWE-787 CVE-2023-46770: Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.
nvd