cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 3 of 56
CVE-2023-39405P3CRITICALCVSS 9.8v2.0.0v2.0.1+2 more2023-08-13
CVE-2023-39405 [CRITICAL] CWE-20 CVE-2023-39405: Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.
nvd
CVE-2023-44106P3CRITICALCVSS 9.8v2.0v2.0.1+5 more2023-10-11
CVE-2023-44106 [CRITICAL] CWE-269 CVE-2023-44106: API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vu API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-41294P3CRITICALCVSS 9.8v2.1.02023-09-25
CVE-2023-41294 [CRITICAL] CWE-400 CVE-2023-41294: The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability ma The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
nvd
CVE-2023-44116P3CRITICALCVSS 9.8v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44116 [CRITICAL] CWE-306 CVE-2023-44116: Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful e Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.
nvd
CVE-2024-57961P3CRITICALCVSS 9.8v3.0.0v4.2.02025-02-06
CVE-2024-57961 [CRITICAL] CWE-787 CVE-2024-57961: Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulner Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-37245P3CRITICALCVSS 9.1v2.0v2.1+3 more2023-07-06
CVE-2023-37245 [CRITICAL] CWE-120 CVE-2023-37245: Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerabi Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
nvd
CVE-2023-52369P3CRITICALCVSS 9.1v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52369 [CRITICAL] CWE-787 CVE-2023-52369: Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may aff Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.
nvd
CVE-2024-30415P3CRITICALCVSS 9.1v2.0.0v2.1.0+3 more2024-04-07
CVE-2024-30415 [CRITICAL] CWE-276 CVE-2024-30415: Vulnerability of improper permission control in the window management module. Impact: Successful exp Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2021-40010P3CRITICALCVSS 9.8v2.02022-01-10
CVE-2021-40010 [CRITICAL] CWE-787 CVE-2021-40010: The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution.
nvd
CVE-2021-37045P3CRITICALCVSS 9.8fixed in 2.0v2.02021-12-08
CVE-2021-37045 [CRITICAL] CWE-416 CVE-2021-37045: There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the kernel-mode code to be executed.
nvd
CVE-2022-39007P3CRITICALCVSS 9.8v2.0v2.12022-09-16
CVE-2022-39007 [CRITICAL] CWE-269 CVE-2022-39007: The location module has a vulnerability of bypassing permission verification.Successful exploitation The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2022-41580P3CRITICALCVSS 9.8v2.02022-10-14
CVE-2022-41580 [CRITICAL] CWE-125 CVE-2022-41580: The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation o The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
nvd
CVE-2022-48512P3CRITICALCVSS 9.8v2.0.02023-07-06
CVE-2022-48512 [CRITICAL] CWE-122 CVE-2022-48512: Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this v Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.
nvd
CVE-2022-48353P3CRITICALCVSS 9.8v2.0v2.0.02023-03-27
CVE-2022-48353 [CRITICAL] CWE-269 CVE-2022-48353: Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions.
nvd
CVE-2021-46894P3CRITICALCVSS 9.8v2.0.02023-07-06
CVE-2021-46894 [CRITICAL] CWE-269 CVE-2021-46894: Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerabilit Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.
nvd
CVE-2023-41297P3CRITICALCVSS 9.8v2.0.02023-09-25
CVE-2023-41297 [CRITICAL] CVE-2023-41297: Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exp Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
nvd
CVE-2024-57959P3CRITICALCVSS 9.8v4.0.0v4.2.0+2 more2025-02-06
CVE-2024-57959 [CRITICAL] CWE-416 CVE-2024-57959: Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vul Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2021-37087P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-07
CVE-2021-37087 [CRITICAL] CWE-22 CVE-2021-37087: There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnera There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create arbitrary file.
nvd
CVE-2021-37088P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-07
CVE-2021-37088 [CRITICAL] CWE-22 CVE-2021-37088: There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnera There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can write any content to any file.
nvd
CVE-2021-40053P3CRITICALCVSS 9.1v2.0v2.12022-03-10
CVE-2021-40053 [CRITICAL] CWE-276 CVE-2021-40053: There is a permission control vulnerability in the Nearby module.Successful exploitation of this vul There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
nvd
Huawei Harmonyos vulnerabilities | cvebase