Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 28 of 56
CVE-2021-37050P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37050 [HIGH] CWE-311 CVE-2021-37050: There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitat
There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48295P3HIGHCVSS 7.5v2.02023-02-09
CVE-2022-48295 [HIGH] CWE-281 CVE-2022-48295: The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulner
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).
nvd
CVE-2022-48301P3HIGHCVSS 7.5v2.0v2.1.0+1 more2023-02-09
CVE-2022-48301 [HIGH] CWE-281 CVE-2022-48301: The bundle management module lacks permission verification in some APIs. Successful exploitation of
The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.
nvd
CVE-2023-44119P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-10-11
CVE-2023-44119 [HIGH] CWE-667 CVE-2023-44119: Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vu
Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-54109P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54109 [HIGH] CWE-125 CVE-2024-54109: Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulner
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-41588P3HIGHCVSS 7.5v2.0v2.12022-10-14
CVE-2022-41588 [HIGH] CWE-1264 CVE-2022-41588: The home screen module has a vulnerability in service logic processing.Successful exploitation of th
The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2024-51518P3HIGHCVSS 7.5v5.0.02024-11-05
CVE-2024-51518 [HIGH] CWE-248 CVE-2024-51518: Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful
Vulnerability of message types not being verified in the advanced messaging modul
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52357P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52357 [HIGH] CWE-502 CVE-2023-52357: Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploi
Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-54106P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54106 [HIGH] CWE-248 CVE-2024-54106: Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation
Null pointer dereference vulnerability in the image decoding module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-54113P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54113 [HIGH] CWE-400 CVE-2024-54113: Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploit
Process residence vulnerability in abnormal scenarios in the print module
Impact: Successful exploitation of this vulnerability may affect power consumption.
nvd
CVE-2024-54108P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54108 [HIGH] CWE-125 CVE-2024-54108: Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulner
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-54116P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54116 [HIGH] CWE-754 CVE-2024-54116: Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerab
Out-of-bounds read vulnerability in the M3U8 module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2024-54107P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54107 [HIGH] CWE-125 CVE-2024-54107: Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulner
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2025-54628P3HIGHCVSS 7.5v4.0.0v4.2.0+4 more2025-08-06
CVE-2025-54628 [HIGH] CWE-118 CVE-2025-54628: Vulnerability of incomplete verification information in the communication module. Impact: Successful
Vulnerability of incomplete verification information in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-39393P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-08-13
CVE-2023-39393 [HIGH] CWE-200 CVE-2023-39393: Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.
nvd
CVE-2023-39392P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-08-13
CVE-2023-39392 [HIGH] CWE-16 CVE-2023-39392: Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnera
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.
nvd
CVE-2024-45441P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-09-04
CVE-2024-45441 [HIGH] CWE-20 CVE-2024-45441: Input verification vulnerability in the system service module Impact: Successful exploitation of thi
Input verification vulnerability in the system service module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-56446P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-56446 [HIGH] CWE-457 CVE-2024-56446: Vulnerability of variables not being initialized in the notification module Impact: Successful explo
Vulnerability of variables not being initialized in the notification module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-54105P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54105 [HIGH] CWE-120 CVE-2024-54105: Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulner
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-45442P3HIGHCVSS 7.5v3.1.0v4.0.0+1 more2024-09-04
CVE-2024-45442 [HIGH] CWE-264 CVE-2024-45442: Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Success
Vulnerability of permission verification for APIs in the DownloadProviderMain module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd