Huawei Harmonyos vulnerabilities

1,076 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,076
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH534MEDIUM365LOW39

Vulnerabilities

Page 36 of 54
CVE-2022-47974MEDIUMCVSS 6.5fixed in 2.0v2.0+2 more2023-01-06
CVE-2022-47974 [MEDIUM] CWE-287 CVE-2022-47974: The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth process to restart.
nvd
CVE-2022-46320CRITICALCVSS 9.8fixed in 2.0v2.0+2 more2022-12-20
CVE-2022-46320 [CRITICAL] CWE-125 CVE-2022-46320: The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerabi The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
nvd
CVE-2022-46327CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46327 [CRITICAL] CWE-269 CVE-2022-46327: Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
nvd
CVE-2022-46326CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46326 [CRITICAL] CWE-787 CVE-2022-46326: Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnera Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
nvd
CVE-2022-46325CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46325 [CRITICAL] CWE-787 CVE-2022-46325: Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerab Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
nvd
CVE-2022-46323CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46323 [CRITICAL] CWE-787 CVE-2022-46323: Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerab Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
nvd
CVE-2022-46324CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46324 [CRITICAL] CWE-787 CVE-2022-46324: Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnera Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
nvd
CVE-2022-46316CRITICALCVSS 9.8fixed in 2.1v2.1+1 more2022-12-20
CVE-2022-46316 [CRITICAL] CWE-287 CVE-2022-46316: A thread security vulnerability exists in the authentication process. Successful exploitation of thi A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
nvd
CVE-2022-46319CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46319 [CRITICAL] CWE-787 CVE-2022-46319: Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
nvd
CVE-2022-46317HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-46317 [HIGH] CWE-125 CVE-2022-46317: The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of thi The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2022-46315HIGHCVSS 7.5fixed in 2.1v2.1+3 more2022-12-20
CVE-2022-46315 [HIGH] CWE-400 CVE-2022-46315: The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnera The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2022-46312HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-46312 [HIGH] CWE-285 CVE-2022-46312: The application management module has a vulnerability in permission verification. Successful exploit The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.
nvd
CVE-2022-46311HIGHCVSS 7.5fixed in 2.0v2.02022-12-20
CVE-2022-46311 [HIGH] CWE-416 CVE-2022-46311: The contacts component has a free (undefined) provider vulnerability. Successful exploitation of thi The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.
nvd
CVE-2022-46321HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-46321 [HIGH] CVE-2022-46321: The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vul The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-41591HIGHCVSS 7.5v2.0v2.1+1 more2022-12-20
CVE-2022-41591 [HIGH] CWE-22 CVE-2022-41591: The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.
nvd
CVE-2021-46856HIGHCVSS 7.5v2.0v3.0.02022-12-20
CVE-2021-46856 [HIGH] CWE-22 CVE-2021-46856: The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-46322HIGHCVSS 7.5fixed in 2.0v2.02022-12-20
CVE-2022-46322 [HIGH] CWE-787 CVE-2022-46322: Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnera Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
nvd
CVE-2022-41599HIGHCVSS 7.5fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-41599 [HIGH] CVE-2022-41599: The system service has a vulnerability that causes incorrect return values. Successful exploitation The system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-46328HIGHCVSS 7.5fixed in 2.1v2.0+1 more2022-12-20
CVE-2022-46328 [HIGH] CWE-20 CVE-2022-46328: Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerabil Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-46310HIGHCVSS 7.5fixed in 3.0.0v3.0.02022-12-20
CVE-2022-46310 [HIGH] CWE-200 CVE-2022-46310: The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.
nvd