Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 34 of 56
CVE-2021-37098P4HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37098 [HIGH] CVE-2021-37098: Hilinksvc service exists a Data Processing Errors vulnerability .Successful exploitation of this vul
Hilinksvc service exists a Data Processing Errors vulnerability .Successful exploitation of this vulnerability may cause application crash.
nvd
CVE-2021-37061P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37061 [HIGH] CWE-400 CVE-2021-37061: There is a Uncontrolled Resource Consumption vulnerability in Huawei Smartphone.Successful exploitat
There is a Uncontrolled Resource Consumption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Screen projection application denial of service.
nvd
CVE-2021-37068P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37068 [HIGH] CVE-2021-37068: There is a Resource Management Errors vulnerability in Huawei Smartphone.Successful exploitation of
There is a Resource Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of Service Attacks.
nvd
CVE-2025-64315P4HIGHCVSS 7.1v5.1.02025-11-28
CVE-2025-64315 [HIGH] CWE-264 CVE-2025-64315: Configuration defect vulnerability in the file management module. Impact: Successful exploitation of
Configuration defect vulnerability in the file management module.
Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.
nvd
CVE-2021-37083P4HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37083 [HIGH] CWE-476 CVE-2021-37083: There is a NULL Pointer Dereference vulnerability in Huawei Smartphone.Successful exploitation of th
There is a NULL Pointer Dereference vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Denial of Service Attacks.
nvd
CVE-2024-42033P4HIGHCVSS 7.1v2.0.0v3.0.0+3 more2024-08-08
CVE-2024-42033 [HIGH] CWE-284 CVE-2024-42033: Access control vulnerability in the security verification module mpact: Successful exploitation of t
Access control vulnerability in the security verification module
mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2025-46585P4HIGHCVSS 7.0v5.0.02025-05-06
CVE-2025-46585 [HIGH] CWE-787 CVE-2025-46585: Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of
Out-of-bounds array read/write vulnerability in the kernel module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52542P4MEDIUMCVSS 6.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52542 [MEDIUM] CWE-281 CVE-2023-52542: Permission verification vulnerability in the system module. Impact: Successful exploitation of this
Permission verification vulnerability in the system module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2022-48291P4MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2023-03-27
CVE-2022-48291 [MEDIUM] CWE-306 CVE-2022-48291: The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful e
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48358P4HIGHCVSS 7.4v3.0.02023-03-27
CVE-2022-48358 [HIGH] CWE-601 CVE-2022-48358: The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerabi
The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service exceptions.
nvd
CVE-2021-22326P4HIGHCVSS 7.1v2.02021-06-30
CVE-2021-22326 [HIGH] CWE-269 CVE-2021-22326: A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attacke
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.
nvd
CVE-2022-41577P4HIGHCVSS 7.1v2.0v2.12022-10-14
CVE-2022-41577 [HIGH] CWE-125 CVE-2022-41577: The kernel server has a vulnerability of not verifying the length of the data transferred in the use
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.
nvd
CVE-2026-24915P4HIGHCVSS 7.1v5.1.0v5.1.1+1 more2026-02-06
CVE-2026-24915 [HIGH] CWE-125 CVE-2026-24915: Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerabili
Out-of-bounds read issue in the media subsystem.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2026-34854P4HIGHCVSS 7.1v4.0.0v4.2.0+4 more2026-04-13
CVE-2026-34854 [HIGH] CWE-416 CVE-2026-34854: UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will a
UAF vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2025-46589P4HIGHCVSS 7.1v5.0.02025-05-06
CVE-2025-46589 [HIGH] CWE-284 CVE-2025-46589: Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this
Vulnerability of unauthorized access in the app lock module
Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
nvd
CVE-2025-58309P4HIGHCVSS 7.1v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-58309 [HIGH] CWE-264 CVE-2025-58309: Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of
Permission control vulnerability in the startup recovery module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2025-58314P4HIGHCVSS 7.1v2.0.0v3.0.0+8 more2025-11-28
CVE-2025-58314 [HIGH] CWE-125 CVE-2025-58314: Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploit
Vulnerability of accessing invalid memory in the component driver module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2026-24921P4HIGHCVSS 7.1v6.0.02026-02-06
CVE-2026-24921 [HIGH] CWE-125 CVE-2026-24921: Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability
Address read vulnerability in the HDC module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2026-41970P4MEDIUMCVSS 6.8v4.3.1v4.3.0+3 more2026-05-15
CVE-2026-41970 [MEDIUM] CWE-787 CVE-2026-41970: Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploita
Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34852P4MEDIUMCVSS 6.5v6.0.02026-04-13
CVE-2026-34852 [MEDIUM] CWE-835 CVE-2026-34852: Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerab
Stack overflow vulnerability in the media platform.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd