Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 33 of 56
CVE-2022-44550P4HIGHCVSS 7.5v2.0v2.12022-11-09
CVE-2022-44550 [HIGH] CWE-416 CVE-2022-44550: The graphics display module has a UAF vulnerability when traversing graphic layers. Successful explo
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2023-52098P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52098 [HIGH] CWE-400 CVE-2023-52098: Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerabili
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-46761P3HIGHCVSS 7.5fixed in 2.0v2.0+2 more2023-01-06
CVE-2022-46761 [HIGH] CWE-276 CVE-2022-46761: The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful e
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.
nvd
CVE-2022-37008P4HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37008 [HIGH] CWE-345 CVE-2022-37008: The recovery module has a vulnerability of bypassing the verification of an update package before us
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
nvd
CVE-2021-37023P4MEDIUMCVSS 6.5v2.02021-11-23
CVE-2021-37023 [MEDIUM] CWE-22 CVE-2021-37023: There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of thi
There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause media files which can be reads and writes in non-distributed directories on any device on the network..
nvd
CVE-2026-34860P4MEDIUMCVSS 6.5v5.1.0v6.0.02026-04-13
CVE-2026-34860 [MEDIUM] CWE-284 CVE-2026-34860: Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerabili
Access control vulnerability in the memo module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2026-41982P3MEDIUMCVSS 6.4v6.1.0v6.0.0+1 more2026-06-09
CVE-2026-41982 [MEDIUM] CWE-416 CVE-2026-41982: Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerabilit
Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52364P4MEDIUMCVSS 6.3v3.0.0v3.1.0+1 more2024-04-08
CVE-2023-52364 [MEDIUM] CWE-120 CVE-2023-52364: Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful
Vulnerability of input parameters being not strictly verified in the RSMC module.
Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.
nvd
CVE-2022-22255P4HIGHCVSS 7.5v2.02022-04-11
CVE-2022-22255 [HIGH] CVE-2022-22255: The application framework has a common DoS vulnerability.Successful exploitation of this vulnerabili
The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2021-37089P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37089 [HIGH] CWE-459 CVE-2021-37089: There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vul
There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel restart.
nvd
CVE-2021-39968P4HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39968 [HIGH] CVE-2021-39968: Changlian Blocklist has a Business Logic Errors vulnerability .Successful exploitation of this vulne
Changlian Blocklist has a Business Logic Errors vulnerability .Successful exploitation of this vulnerability may expand the attack surface of the message class.
nvd
CVE-2021-39984P4HIGHCVSS 7.5v2.02022-01-03
CVE-2021-39984 [HIGH] CWE-125 CVE-2021-39984: Huawei idap module has a Out-of-bounds Read vulnerability.Successful exploitation of this vulnerabil
Huawei idap module has a Out-of-bounds Read vulnerability.Successful exploitation of this vulnerability may cause Denial of Service.
nvd
CVE-2021-37071P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37071 [HIGH] CVE-2021-37071: There is a Business Logic Errors vulnerability in Huawei Smartphone.Successful exploitation of this
There is a Business Logic Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to persistent dos.
nvd
CVE-2021-37072P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37072 [HIGH] CWE-415 CVE-2021-37072: There is a Incorrect Calculation of Buffer Size vulnerability in Huawei Smartphone.Successful exploi
There is a Incorrect Calculation of Buffer Size vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory crash.
nvd
CVE-2022-39005P4HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-39005 [HIGH] CWE-401 CVE-2022-39005: The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability ca
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
nvd
CVE-2022-39004P4HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-39004 [HIGH] CWE-401 CVE-2022-39004: The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability ca
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
nvd
CVE-2022-48357P4HIGHCVSS 7.5v2.0v2.0.1+2 more2023-03-27
CVE-2022-48357 [HIGH] CWE-770 CVE-2022-48357: Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.
nvd
CVE-2025-48909P4HIGHCVSS 7.1v5.0.02025-06-06
CVE-2025-48909 [HIGH] CWE-287 CVE-2025-48909: Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulner
Bypass vulnerability in the device management channel
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54099P4HIGHCVSS 7.1v3.0.0v3.1.0+2 more2024-12-12
CVE-2024-54099 [HIGH] CWE-552 CVE-2024-54099: File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability
File replacement vulnerability on some devices
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2021-39975P4HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39975 [HIGH] CVE-2021-39975: Hilinksvc has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability m
Hilinksvc has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause denial of service attacks.
nvd