Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 39 of 56
CVE-2025-54644P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2025-08-06
CVE-2025-54644 [MEDIUM] CWE-125 CVE-2025-54644: Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light m
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-58284P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58284 [MEDIUM] CWE-264 CVE-2025-58284: Permission control vulnerability in the network module. Successful exploitation of this vulnerabilit
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-58282P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58282 [MEDIUM] CWE-264 CVE-2025-58282: Permission control vulnerability in the camera module. Successful exploitation of this vulnerability
Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-64311P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-64311 [MEDIUM] CWE-200 CVE-2025-64311: Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vuln
Permission control vulnerability in the Notepad module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-66325P4MEDIUMCVSS 5.5v2.0.0v3.0.0+5 more2025-12-08
CVE-2025-66325 [MEDIUM] CWE-264 CVE-2025-66325: Permission control vulnerability in the package management module. Impact: Successful exploitation o
Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-68966P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2026-01-14
CVE-2025-68966 [MEDIUM] CWE-200 CVE-2025-68966: Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vuln
Permission control vulnerability in the Notepad module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-68965P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2026-01-14
CVE-2025-68965 [MEDIUM] CWE-200 CVE-2025-68965: Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vuln
Permission control vulnerability in the Notepad module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-58279P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-12-08
CVE-2025-58279 [MEDIUM] CWE-200 CVE-2025-58279: Permission control vulnerability in the media library module. Impact: Successful exploitation of thi
Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37132P4MEDIUMCVSS 5.3fixed in 2.0v2.02022-01-03
CVE-2021-37132 [MEDIUM] CWE-276 CVE-2021-37132: PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful e
PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.
nvd
CVE-2021-46785P4MEDIUMCVSS 5.3v2.02022-05-13
CVE-2021-46785 [MEDIUM] CVE-2021-46785: The Property module has a vulnerability in permission control.This vulnerability can be exploited to
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.
nvd
CVE-2021-46811P4MEDIUMCVSS 5.3v2.02022-06-13
CVE-2021-46811 [MEDIUM] CWE-276 CVE-2021-46811: HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnera
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.
nvd
CVE-2022-46313P4MEDIUMCVSS 5.3fixed in 3.0.0v3.0.02022-12-20
CVE-2022-46313 [MEDIUM] CWE-287 CVE-2022-46313: The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulne
The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.
nvd
CVE-2023-6273P4MEDIUMCVSS 5.3v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-6273 [MEDIUM] CWE-276 CVE-2023-6273: Permission management vulnerability in the module for disabling Sound Booster. Successful exploitati
Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2022-48361P4MEDIUMCVSS 5.3v3.0.02023-03-27
CVE-2022-48361 [MEDIUM] CWE-22 CVE-2022-48361: The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitati
The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in reading AOD theme resources.
nvd
CVE-2023-41312P4MEDIUMCVSS 5.3v2.0.1v3.0.0+2 more2023-09-27
CVE-2023-41312 [MEDIUM] CWE-269 CVE-2023-41312: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
nvd
CVE-2023-44102P4MEDIUMCVSS 5.3v2.0.1v3.0.0+2 more2023-10-11
CVE-2023-44102 [MEDIUM] CWE-668 CVE-2023-44102: Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this v
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.
nvd
CVE-2023-41311P4MEDIUMCVSS 5.3v2.0.1v3.0.0+2 more2023-09-27
CVE-2023-41311 [MEDIUM] CWE-284 CVE-2023-41311: Permission control vulnerability in the audio module. Successful exploitation of this vulnerability
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
nvd
CVE-2023-52112P4MEDIUMCVSS 5.3v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52112 [MEDIUM] CWE-552 CVE-2023-52112: Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of t
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2023-46763P4MEDIUMCVSS 5.3v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-46763 [MEDIUM] CWE-20 CVE-2023-46763: Vulnerability of background app permission management in the framework module. Successful exploitati
Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.
nvd
CVE-2022-46318P4MEDIUMCVSS 5.3fixed in 2.1v2.0+2 more2022-12-20
CVE-2022-46318 [MEDIUM] CVE-2022-46318: The HAware module has a function logic error. Successful exploitation of this vulnerability will aff
The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings.
nvd