cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 33 of 56
CVE-2022-44550P4HIGHCVSS 7.5v2.0v2.12022-11-09
CVE-2022-44550 [HIGH] CWE-416 CVE-2022-44550: The graphics display module has a UAF vulnerability when traversing graphic layers. Successful explo The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2023-52098P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52098 [HIGH] CWE-400 CVE-2023-52098: Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerabili Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-46761P3HIGHCVSS 7.5fixed in 2.0v2.0+2 more2023-01-06
CVE-2022-46761 [HIGH] CWE-276 CVE-2022-46761: The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful e The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.
nvd
CVE-2022-37008P4HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37008 [HIGH] CWE-345 CVE-2022-37008: The recovery module has a vulnerability of bypassing the verification of an update package before us The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
nvd
CVE-2021-37023P4MEDIUMCVSS 6.5v2.02021-11-23
CVE-2021-37023 [MEDIUM] CWE-22 CVE-2021-37023: There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of thi There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause media files which can be reads and writes in non-distributed directories on any device on the network..
nvd
CVE-2026-34860P4MEDIUMCVSS 6.5v5.1.0v6.0.02026-04-13
CVE-2026-34860 [MEDIUM] CWE-284 CVE-2026-34860: Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerabili Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2026-41982P3MEDIUMCVSS 6.4v6.1.0v6.0.0+1 more2026-06-09
CVE-2026-41982 [MEDIUM] CWE-416 CVE-2026-41982: Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerabilit Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52364P4MEDIUMCVSS 6.3v3.0.0v3.1.0+1 more2024-04-08
CVE-2023-52364 [MEDIUM] CWE-120 CVE-2023-52364: Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.
nvd
CVE-2022-22255P4HIGHCVSS 7.5v2.02022-04-11
CVE-2022-22255 [HIGH] CVE-2022-22255: The application framework has a common DoS vulnerability.Successful exploitation of this vulnerabili The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2021-37089P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37089 [HIGH] CWE-459 CVE-2021-37089: There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vul There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel restart.
nvd
CVE-2021-39968P4HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39968 [HIGH] CVE-2021-39968: Changlian Blocklist has a Business Logic Errors vulnerability .Successful exploitation of this vulne Changlian Blocklist has a Business Logic Errors vulnerability .Successful exploitation of this vulnerability may expand the attack surface of the message class.
nvd
CVE-2021-39984P4HIGHCVSS 7.5v2.02022-01-03
CVE-2021-39984 [HIGH] CWE-125 CVE-2021-39984: Huawei idap module has a Out-of-bounds Read vulnerability.Successful exploitation of this vulnerabil Huawei idap module has a Out-of-bounds Read vulnerability.Successful exploitation of this vulnerability may cause Denial of Service.
nvd
CVE-2021-37071P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37071 [HIGH] CVE-2021-37071: There is a Business Logic Errors vulnerability in Huawei Smartphone.Successful exploitation of this There is a Business Logic Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to persistent dos.
nvd
CVE-2021-37072P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37072 [HIGH] CWE-415 CVE-2021-37072: There is a Incorrect Calculation of Buffer Size vulnerability in Huawei Smartphone.Successful exploi There is a Incorrect Calculation of Buffer Size vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory crash.
nvd
CVE-2022-39005P4HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-39005 [HIGH] CWE-401 CVE-2022-39005: The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability ca The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
nvd
CVE-2022-39004P4HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-39004 [HIGH] CWE-401 CVE-2022-39004: The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability ca The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
nvd
CVE-2022-48357P4HIGHCVSS 7.5v2.0v2.0.1+2 more2023-03-27
CVE-2022-48357 [HIGH] CWE-770 CVE-2022-48357: Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.
nvd
CVE-2025-48909P4HIGHCVSS 7.1v5.0.02025-06-06
CVE-2025-48909 [HIGH] CWE-287 CVE-2025-48909: Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulner Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54099P4HIGHCVSS 7.1v3.0.0v3.1.0+2 more2024-12-12
CVE-2024-54099 [HIGH] CWE-552 CVE-2024-54099: File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2021-39975P4HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39975 [HIGH] CVE-2021-39975: Hilinksvc has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability m Hilinksvc has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause denial of service attacks.
nvd
Huawei Harmonyos vulnerabilities | cvebase