Huawei Harmonyos vulnerabilities
1,076 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,076
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH534MEDIUM365LOW39
Vulnerabilities
Page 25 of 54
CVE-2023-49240HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49240 [HIGH] CWE-601 CVE-2023-49240: Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerabil
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49239HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49239 [HIGH] CWE-863 CVE-2023-49239: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44113HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-44113 [HIGH] CWE-862 CVE-2023-44113: Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) modu
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49245HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49245 [HIGH] CVE-2023-49245: Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulner
Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49244HIGHCVSS 7.5v2.1.0v3.0.0+2 more2023-12-06
CVE-2023-49244 [HIGH] CVE-2023-49244: Permission management vulnerability in the multi-user module. Successful exploitation of this vulner
Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49242HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49242 [HIGH] CVE-2023-49242: Free broadcast vulnerability in the running management module. Successful exploitation of this vulne
Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49243HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49243 [HIGH] CVE-2023-49243: Vulnerability of unauthorized access to email attachments in the email module. Successful exploitati
Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44099HIGHCVSS 7.5v2.0.0v2.1.0+2 more2023-12-06
CVE-2023-44099 [HIGH] CWE-754 CVE-2023-44099: Vulnerability of data verification errors in the kernel module. Successful exploitation of this vuln
Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.
nvd
CVE-2023-49246HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49246 [HIGH] CWE-863 CVE-2023-49246: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49247HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49247 [HIGH] CWE-295 CVE-2023-49247: Permission verification vulnerability in distributed scenarios. Successful exploitation of this vuln
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49241HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49241 [HIGH] CVE-2023-49241: API permission control vulnerability in the network management module. Successful exploitation of th
API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-6273MEDIUMCVSS 5.3v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-6273 [MEDIUM] CWE-276 CVE-2023-6273: Permission management vulnerability in the module for disabling Sound Booster. Successful exploitati
Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-49248MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49248 [MEDIUM] CWE-20 CVE-2023-49248: Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulne
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
nvd
CVE-2023-5801CRITICALCVSS 9.1v2.0.0v3.0.0+1 more2023-11-08
CVE-2023-5801 [CRITICAL] CWE-290 CVE-2023-5801: Vulnerability of identity verification being bypassed in the face unlock module. Successful exploita
Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2023-46771HIGHCVSS 7.5v2.0.0v3.0.0+1 more2023-11-08
CVE-2023-46771 [HIGH] CWE-269 CVE-2023-46771: Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46761HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46761 [HIGH] CWE-787 CVE-2023-46761: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46767HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46767 [HIGH] CWE-125 CVE-2023-46767: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46758HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46758 [HIGH] CWE-269 CVE-2023-46758: Permission management vulnerability in the multi-screen interaction module. Successful exploitation
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
nvd
CVE-2023-44115HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-44115 [HIGH] CWE-200 CVE-2023-44115: Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation
Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46770HIGHCVSS 7.5v2.0.0v3.0.0+1 more2023-11-08
CVE-2023-46770 [HIGH] CWE-787 CVE-2023-46770: Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may
Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.
nvd