cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 4 of 56
CVE-2022-34737P3CRITICALCVSS 9.1v2.02022-07-12
CVE-2022-34737 [CRITICAL] CWE-276 CVE-2022-34737: The application security module has a vulnerability in permission assignment. Successful exploitatio The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
nvd
CVE-2021-46840P3CRITICALCVSS 9.1v2.02022-10-14
CVE-2021-46840 [CRITICAL] CWE-125 CVE-2021-46840: The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Succ The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
nvd
CVE-2023-39402P3CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39402 [CRITICAL] CWE-22 CVE-2023-39402: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-39401P3CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39401 [CRITICAL] CWE-22 CVE-2023-39401: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-39400P3CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39400 [CRITICAL] CWE-22 CVE-2023-39400: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2026-34865P3CRITICALCVSS 9.1v6.0.02026-04-13
CVE-2026-34865 [CRITICAL] CWE-122 CVE-2026-34865: Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerab Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2021-37049P3CRITICALCVSS 9.8fixed in 2.0v2.02021-12-08
CVE-2021-37049 [CRITICAL] CWE-787 CVE-2021-37049: There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may rewrite the memory of adjacent objects.
nvd
CVE-2021-39996P3CRITICALCVSS 9.8fixed in 2.02022-01-10
CVE-2021-39996 [CRITICAL] CWE-787 CVE-2021-39996: There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful e There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.
nvd
CVE-2022-29794P3CRITICALCVSS 9.8v2.02022-05-13
CVE-2022-29794 [CRITICAL] CWE-416 CVE-2022-29794: The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.
nvd
CVE-2023-44112P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-44112 [HIGH] CWE-200 CVE-2023-44112: Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of t Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-38980P3CRITICALCVSS 9.8v2.0v2.12022-10-14
CVE-2022-38980 [CRITICAL] CWE-787 CVE-2022-38980: The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
nvd
CVE-2025-54607P3HIGHCVSS 7.5v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54607 [HIGH] CWE-295 CVE-2025-54607: Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of thi Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48510P3CRITICALCVSS 9.8v2.0.02023-07-06
CVE-2022-48510 [CRITICAL] CWE-200 CVE-2022-48510: Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability wi Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.
nvd
CVE-2022-46319P3CRITICALCVSS 9.8fixed in 2.0v2.02022-12-20
CVE-2022-46319 [CRITICAL] CWE-787 CVE-2022-46319: Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
nvd
CVE-2023-34159P3CRITICALCVSS 9.8v3.1.0vunspecified2023-06-19
CVE-2023-34159 [CRITICAL] CVE-2023-34159: Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerab Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.
nvd
CVE-2023-52103P3CRITICALCVSS 9.8v3.0.0v3.1.0+1 more2024-01-16
CVE-2023-52103 [CRITICAL] CWE-120 CVE-2023-52103: Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may c Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.
nvd
CVE-2021-46891P3CRITICALCVSS 9.8v2.0v2.0.02023-07-05
CVE-2021-46891 [CRITICAL] CWE-200 CVE-2021-46891: Vulnerability of incomplete read and write permission verification in the GPU module. Successful exp Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
nvd
CVE-2021-46890P3CRITICALCVSS 9.8v2.0v2.0.02023-07-05
CVE-2021-46890 [CRITICAL] CWE-863 CVE-2021-46890: Vulnerability of incomplete read and write permission verification in the GPU module. Successful exp Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
nvd
CVE-2022-44551P3CRITICALCVSS 9.8v2.0v2.12022-11-09
CVE-2022-44551 [CRITICAL] CWE-362 CVE-2022-44551: The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerabil The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
nvd
CVE-2022-48605P3CRITICALCVSS 9.8v4.0.0v3.1.0+1 more2023-09-25
CVE-2022-48605 [CRITICAL] CWE-20 CVE-2022-48605: Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerab Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
nvd
Huawei Harmonyos vulnerabilities | cvebase