Huawei Harmonyos vulnerabilities

1,076 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,076
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH534MEDIUM365LOW39

Vulnerabilities

Page 34 of 54
CVE-2022-48348CRITICALCVSS 9.1v3.0.02023-03-27
CVE-2022-48348 [CRITICAL] CWE-200 CVE-2022-48348: The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of t The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and integrity.
nvd
CVE-2022-48346HIGHCVSS 7.5v2.0v2.0.1+4 more2023-03-27
CVE-2022-48346 [HIGH] CWE-200 CVE-2022-48346: The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerabilit The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-26549HIGHCVSS 7.5v2.0v2.0.1+5 more2023-03-27
CVE-2023-26549 [HIGH] CWE-233 CVE-2023-26549: The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successf The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-26547HIGHCVSS 7.8v2.0v2.0.1+5 more2023-03-27
CVE-2023-26547 [HIGH] CWE-502 CVE-2023-26547: The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exp The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
nvd
CVE-2022-48360HIGHCVSS 7.5v2.0.0v2.1.0+1 more2023-03-27
CVE-2022-48360 [HIGH] CWE-276 CVE-2022-48360: The facial recognition module has a vulnerability in file permission control. Successful exploitatio The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48358HIGHCVSS 7.4v3.0.02023-03-27
CVE-2022-48358 [HIGH] CWE-601 CVE-2022-48358: The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerabi The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service exceptions.
nvd
CVE-2022-48351HIGHCVSS 7.5v2.0v2.0.1+2 more2023-03-27
CVE-2022-48351 [HIGH] CWE-400 CVE-2022-48351: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-48356HIGHCVSS 7.5v2.0v2.0.02023-03-27
CVE-2022-48356 [HIGH] CWE-20 CVE-2022-48356: The facial recognition module has a vulnerability in input parameter verification. Successful exploi The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition.
nvd
CVE-2022-48357HIGHCVSS 7.5v2.0v2.0.1+2 more2023-03-27
CVE-2022-48357 [HIGH] CWE-770 CVE-2022-48357: Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.
nvd
CVE-2022-48350HIGHCVSS 7.5v3.0.02023-03-27
CVE-2022-48350 [HIGH] CWE-862 CVE-2022-48350: The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48359HIGHCVSS 7.5v2.0v2.0.1+4 more2023-03-27
CVE-2022-48359 [HIGH] CWE-915 CVE-2022-48359: The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successfu The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-26548HIGHCVSS 7.5v2.0v2.0.1+5 more2023-03-27
CVE-2023-26548 [HIGH] CWE-502 CVE-2023-26548: The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of th The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2022-48347HIGHCVSS 7.5v3.0.02023-03-27
CVE-2022-48347 [HIGH] CWE-200 CVE-2022-48347: The MediaProvider module has a vulnerability in permission verification. Successful exploitation of The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48352HIGHCVSS 7.5v2.0v3.0.0+1 more2023-03-27
CVE-2022-48352 [HIGH] CWE-665 CVE-2022-48352: Some smartphones have data initialization issues. Successful exploitation of this vulnerability may Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.
nvd
CVE-2022-48361MEDIUMCVSS 5.3v3.0.02023-03-27
CVE-2022-48361 [MEDIUM] CWE-22 CVE-2022-48361: The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitati The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in reading AOD theme resources.
nvd
CVE-2022-48354MEDIUMCVSS 6.5v2.0v2.1.0+3 more2023-03-27
CVE-2022-48354 [MEDIUM] CWE-787 CVE-2022-48354: The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this v The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
nvd
CVE-2022-48291MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2023-03-27
CVE-2022-48291 [MEDIUM] CWE-306 CVE-2022-48291: The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful e The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48355MEDIUMCVSS 6.5v2.0.0v2.1.0+2 more2023-03-27
CVE-2022-48355 [MEDIUM] CWE-787 CVE-2022-48355: The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vu The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
nvd
CVE-2022-48290CRITICALCVSS 9.1v3.0.02023-02-09
CVE-2022-48290 [CRITICAL] CWE-693 CVE-2022-48290: The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity.
nvd
CVE-2022-48287HIGHCVSS 7.5v2.0v2.1+1 more2023-02-09
CVE-2022-48287 [HIGH] CWE-693 CVE-2022-48287: The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerabilit The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
nvd