Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 27 of 56
CVE-2022-47976P3HIGHCVSS 7.5fixed in 2.0v2.0+2 more2023-01-06
CVE-2022-47976 [HIGH] CWE-287 CVE-2022-47976: The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control con
The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.
nvd
CVE-2023-44108P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44108 [HIGH] CWE-843 CVE-2023-44108: Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerab
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2022-41596P3HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-41596 [HIGH] CWE-502 CVE-2022-41596: The system tool has inconsistent serialization and deserialization. Successful exploitation of this
The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.
nvd
CVE-2023-52552P3HIGHCVSS 7.5v2.1.0v3.0.0+2 more2024-04-08
CVE-2023-52552 [HIGH] CWE-20 CVE-2023-52552: Input verification vulnerability in the power module. Impact: Successful exploitation of this vulner
Input verification vulnerability in the power module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-52366P3HIGHCVSS 7.5v2.0.0v3.0.0+2 more2024-02-18
CVE-2023-52366 [HIGH] CWE-120 CVE-2023-52366: Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of
Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-52108P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52108 [HIGH] CVE-2023-52108: Vulnerability of process priorities being raised in the ActivityManagerService module. Successful ex
Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-39408P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-39408 [HIGH] CWE-120 CVE-2023-39408: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2023-39395P3HIGHCVSS 7.5v2.0.0v3.0.0+1 more2023-08-13
CVE-2023-39395 [HIGH] CWE-19 CVE-2023-39395: Mismatch vulnerability in the serialization process in the communication system. Successful exploita
Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-39381P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39381 [HIGH] CWE-20 CVE-2023-39381: Input verification vulnerability in the storage module. Successful exploitation of this vulnerabili
Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2023-39397P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-08-13
CVE-2023-39397 [HIGH] CWE-476 CVE-2023-39397: Input parameter verification vulnerability in the communication system. Successful exploitation of t
Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-38977P3HIGHCVSS 7.5v2.0v2.12022-10-14
CVE-2022-38977 [HIGH] CWE-787 CVE-2022-38977: The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability
The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.
nvd
CVE-2023-41299P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-09-25
CVE-2023-41299 [HIGH] CWE-120 CVE-2023-41299: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2023-39409P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-39409 [HIGH] CWE-120 CVE-2023-39409: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2022-41583P3HIGHCVSS 7.5v2.02022-10-14
CVE-2022-41583 [HIGH] CWE-125 CVE-2022-41583: The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successfu
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.
nvd
CVE-2023-52537P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52537 [HIGH] CWE-280 CVE-2023-52537: Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful ex
Vulnerability of package name verification being bypassed in the HwIms module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-52362P3HIGHCVSS 7.5v3.0.0v3.1.0+1 more2024-02-18
CVE-2023-52362 [HIGH] CWE-276 CVE-2023-52362: Permission management vulnerability in the lock screen module.Successful exploitation of this vulner
Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52359P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52359 [HIGH] CWE-285 CVE-2023-52359: Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impa
Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-52716P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-07
CVE-2023-52716 [HIGH] CWE-269 CVE-2023-52716: Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. I
Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-58111P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58111 [HIGH] CWE-248 CVE-2024-58111: Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Suc
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58112P3HIGHCVSS 7.5v5.0.02025-04-07
CVE-2024-58112 [HIGH] CWE-248 CVE-2024-58112: Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Suc
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect availability.
nvd