Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 30 of 56
CVE-2021-39989P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39989 [HIGH] CWE-704 CVE-2021-39989: The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerabili
The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
nvd
CVE-2021-37094P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37094 [HIGH] CWE-20 CVE-2021-37094: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service.
nvd
CVE-2021-37081P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37081 [HIGH] CWE-20 CVE-2021-37081: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to nearby crash.
nvd
CVE-2022-22261P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-22261 [HIGH] CVE-2022-22261: The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Success
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
nvd
CVE-2022-29796P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29796 [HIGH] CVE-2022-29796: The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Success
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
nvd
CVE-2022-29791P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29791 [HIGH] CVE-2022-29791: The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Success
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
nvd
CVE-2022-29789P3HIGHCVSS 7.5v2.02022-05-13
CVE-2022-29789 [HIGH] CVE-2022-29789: The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Suc
The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services.
nvd
CVE-2022-37004P3HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37004 [HIGH] CVE-2022-37004: The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successf
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2022-37007P3HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37007 [HIGH] CWE-125 CVE-2022-37007: The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnera
The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2021-40034P3HIGHCVSS 7.5v2.02022-08-10
CVE-2021-40034 [HIGH] CVE-2021-40034: The video framework has the memory overwriting vulnerability caused by addition overflow. Successful
The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2022-48356P3HIGHCVSS 7.5v2.0v2.0.02023-03-27
CVE-2022-48356 [HIGH] CWE-20 CVE-2022-48356: The facial recognition module has a vulnerability in input parameter verification. Successful exploi
The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition.
nvd
CVE-2022-46317P3HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-46317 [HIGH] CWE-125 CVE-2022-46317: The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of thi
The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2022-44554P3HIGHCVSS 7.5v2.02022-11-09
CVE-2022-44554 [HIGH] CWE-276 CVE-2022-44554: The power module has a vulnerability in permission verification. Successful exploitation of this vul
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
nvd
CVE-2023-34155P3HIGHCVSS 7.5v3.1.0vunspecified2023-06-19
CVE-2023-34155 [HIGH] CVE-2023-34155: Vulnerability of unauthorized calling on HUAWEI phones and tablets.Successful exploitation of this v
Vulnerability of unauthorized calling on HUAWEI phones and tablets.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-34166P3HIGHCVSS 7.5v3.1.0v3.0.0+3 more2023-06-19
CVE-2023-34166 [HIGH] CWE-400 CVE-2023-34166: Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitati
Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to restart.
nvd
CVE-2021-46881P3HIGHCVSS 7.5v2.1.0v2.0.1+1 more2023-05-26
CVE-2021-46881 [HIGH] CWE-120 CVE-2021-46881: The video framework has memory overwriting caused by addition overflow. Successful exploitation of t
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46883P3HIGHCVSS 7.5v2.1.0v2.0.1+1 more2023-05-26
CVE-2021-46883 [HIGH] CWE-120 CVE-2021-46883: The video framework has memory overwriting caused by addition overflow. Successful exploitation of t
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46882P3HIGHCVSS 7.5v2.1.0v2.0.1+1 more2023-05-26
CVE-2021-46882 [HIGH] CWE-120 CVE-2021-46882: The video framework has memory overwriting caused by addition overflow. Successful exploitation of t
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46884P3HIGHCVSS 7.5v2.1.0v2.0.1+1 more2023-05-26
CVE-2021-46884 [HIGH] CWE-120 CVE-2021-46884: The video framework has memory overwriting caused by addition overflow. Successful exploitation of t
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-46886P3HIGHCVSS 7.5v2.1.0v2.0.1+1 more2023-05-26
CVE-2021-46886 [HIGH] CWE-120 CVE-2021-46886: The video framework has memory overwriting caused by addition overflow. Successful exploitation of t
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
nvd