Huawei Harmonyos vulnerabilities
1,076 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,076
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH534MEDIUM365LOW39
Vulnerabilities
Page 26 of 54
CVE-2023-46762HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46762 [HIGH] CWE-125 CVE-2023-46762: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46760HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46760 [HIGH] CWE-787 CVE-2023-46760: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-44098HIGHCVSS 7.5v2.0.1v2.1.0+3 more2023-11-08
CVE-2023-44098 [HIGH] CWE-200 CVE-2023-44098: Vulnerability of missing encryption in the card management module. Successful exploitation of this v
Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46766HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46766 [HIGH] CWE-125 CVE-2023-46766: Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulne
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
nvd
CVE-2023-46759HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46759 [HIGH] CWE-284 CVE-2023-46759: Permission control vulnerability in the call module. Successful exploitation of this vulnerability m
Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-46769HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46769 [HIGH] CWE-416 CVE-2023-46769: Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerabili
Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-46774HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46774 [HIGH] CVE-2023-46774: Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerabilit
Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.
nvd
CVE-2023-46765HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46765 [HIGH] CWE-754 CVE-2023-46765: Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerabilit
Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.
nvd
CVE-2023-46757HIGHCVSS 7.5v4.0.02023-11-08
CVE-2023-46757 [HIGH] CWE-200 CVE-2023-46757: The remote PIN module has a vulnerability that causes incorrect information storage locations.Succes
The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-46768HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-11-08
CVE-2023-46768 [HIGH] CWE-416 CVE-2023-46768: Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may ca
Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2022-48613MEDIUMCVSS 5.9v2.0.0v3.0.02023-11-08
CVE-2022-48613 [MEDIUM] CWE-362 CVE-2022-48613: Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may
Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.
nvd
CVE-2023-46755MEDIUMCVSS 5.3v2.0.0v2.0.1+2 more2023-11-08
CVE-2023-46755 [MEDIUM] CWE-284 CVE-2023-46755: Vulnerability of input parameters being not strictly verified in the input. Successful exploitation
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
nvd
CVE-2023-46763MEDIUMCVSS 5.3v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46763 [MEDIUM] CWE-20 CVE-2023-46763: Vulnerability of background app permission management in the framework module. Successful exploitati
Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.
nvd
CVE-2023-46764MEDIUMCVSS 5.3v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46764 [MEDIUM] CWE-15 CVE-2023-46764: Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability
Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.
nvd
CVE-2023-46756MEDIUMCVSS 5.3v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46756 [MEDIUM] CWE-269 CVE-2023-46756: Permission control vulnerability in the window management module. Successful exploitation of this vu
Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
nvd
CVE-2023-44106CRITICALCVSS 9.8v2.0v2.0.1+5 more2023-10-11
CVE-2023-44106 [CRITICAL] CWE-269 CVE-2023-44106: API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vu
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-44118CRITICALCVSS 9.1v2.0.0v3.0.02023-10-11
CVE-2023-44118 [CRITICAL] CWE-284 CVE-2023-44118: Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnera
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2023-44107CRITICALCVSS 9.1v2.1.02023-10-11
CVE-2023-44107 [CRITICAL] CVE-2023-44107: Vulnerability of defects introduced in the design process in the screen projection module.Successfu
Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.
nvd
CVE-2023-44116CRITICALCVSS 9.8v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44116 [CRITICAL] CWE-306 CVE-2023-44116: Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful e
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.
nvd
CVE-2023-44105CRITICALCVSS 9.8v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44105 [CRITICAL] CWE-269 CVE-2023-44105: Vulnerability of permissions not being strictly verified in the window management module.Successful
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd