Huawei Harmonyos vulnerabilities

1,076 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,076
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH534MEDIUM365LOW39

Vulnerabilities

Page 28 of 54
CVE-2023-41307HIGHCVSS 7.5v2.0.0v2.1.0+1 more2023-09-27
CVE-2023-41307 [HIGH] CWE-787 CVE-2023-41307: Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerabili Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-41309HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-27
CVE-2023-41309 [HIGH] CWE-269 CVE-2023-41309: Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of t Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-41312MEDIUMCVSS 5.3v2.0.1v3.0.0+2 more2023-09-27
CVE-2023-41312 [MEDIUM] CWE-269 CVE-2023-41312: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
nvd
CVE-2023-4565MEDIUMCVSS 5.3v2.0.0v2.0.1+4 more2023-09-27
CVE-2023-4565 [MEDIUM] CWE-732 CVE-2023-4565: Broadcast permission control vulnerability in the framework module. Successful exploitation of this Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable.
nvd
CVE-2023-41311MEDIUMCVSS 5.3v2.0.1v3.0.0+2 more2023-09-27
CVE-2023-41311 [MEDIUM] CWE-284 CVE-2023-41311: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
nvd
CVE-2023-41306LOWCVSS 3.7v2.0.0v2.0.12023-09-27
CVE-2023-41306 [LOW] CWE-362 CVE-2023-41306: Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful e Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.
nvd
CVE-2023-41310LOWCVSS 3.3v2.0.0v2.0.1+4 more2023-09-27
CVE-2023-41310 [LOW] CWE-400 CVE-2023-41310: Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerab Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background.
nvd
CVE-2023-39407CRITICALCVSS 9.1v2.0.02023-09-25
CVE-2023-39407 [CRITICAL] CWE-22 CVE-2023-39407: The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability ma The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
nvd
CVE-2023-41294CRITICALCVSS 9.8v2.1.02023-09-25
CVE-2023-41294 [CRITICAL] CWE-400 CVE-2023-41294: The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability ma The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
nvd
CVE-2023-41297CRITICALCVSS 9.8v2.0.02023-09-25
CVE-2023-41297 [CRITICAL] CVE-2023-41297: Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exp Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
nvd
CVE-2023-41296CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-41296 [CRITICAL] CWE-862 CVE-2023-41296: Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnera Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
nvd
CVE-2022-48605CRITICALCVSS 9.8v4.0.0v3.1.0+1 more2023-09-25
CVE-2022-48605 [CRITICAL] CWE-20 CVE-2022-48605: Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerab Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
nvd
CVE-2023-41301HIGHCVSS 7.5v2.0.0v2.0.1+2 more2023-09-25
CVE-2023-41301 [HIGH] CWE-269 CVE-2023-41301: Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerab Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-41303HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-41303 [HIGH] CWE-20 CVE-2023-41303: Command injection vulnerability in the distributed file system module. Successful exploitation of th Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.
nvd
CVE-2023-41299HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-09-25
CVE-2023-41299 [HIGH] CWE-120 CVE-2023-41299: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2023-41293HIGHCVSS 7.5v3.0.0v3.1.0+1 more2023-09-25
CVE-2023-41293 [HIGH] CWE-227 CVE-2023-41293: Data security classification vulnerability in the DDMP module. Successful exploitation of this vulne Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-41298HIGHCVSS 7.5v2.0.1v3.0.0+2 more2023-09-25
CVE-2023-41298 [HIGH] CVE-2023-41298: Vulnerability of permission control in the window module. Successful exploitation of this vulnerabil Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-39409HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-39409 [HIGH] CWE-120 CVE-2023-39409: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2023-39408HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-39408 [HIGH] CWE-120 CVE-2023-39408: DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the sys DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2023-41300HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-41300 [HIGH] CWE-20 CVE-2023-41300: Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation o Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
nvd