Huawei Harmonyos vulnerabilities
1,076 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,076
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH534MEDIUM365LOW39
Vulnerabilities
Page 41 of 54
CVE-2022-38978HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-38978 [HIGH] CVE-2022-38978: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40024HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2021-40024 [HIGH] CVE-2021-40024: Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successfu
Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-39010HIGHCVSS 7.5v2.02022-09-16
CVE-2022-39010 [HIGH] CVE-2022-39010: The HwChrService module has a vulnerability in permission control. Successful exploitation of this v
The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information.
nvd
CVE-2022-38996HIGHCVSS 7.5v2.0v2.12022-09-16
CVE-2022-38996 [HIGH] CVE-2022-38996: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2022-38988HIGHCVSS 7.5v2.02022-09-16
CVE-2022-38988 [HIGH] CVE-2022-38988: The secure OS module has configuration defects. Successful exploitation of this vulnerability may af
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-39006MEDIUMCVSS 5.9v2.0v2.12022-09-16
CVE-2022-39006 [MEDIUM] CWE-362 CVE-2022-39006: The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
nvd
CVE-2022-37002CRITICALCVSS 9.8v2.02022-08-10
CVE-2022-37002 [CRITICAL] CWE-269 CVE-2022-37002: The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulner
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
nvd
CVE-2022-37003CRITICALCVSS 9.8v2.02022-08-10
CVE-2022-37003 [CRITICAL] CWE-276 CVE-2022-37003: The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnera
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
nvd
CVE-2022-37004HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37004 [HIGH] CVE-2022-37004: The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successf
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2022-37007HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37007 [HIGH] CWE-125 CVE-2022-37007: The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnera
The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2021-40040HIGHCVSS 7.5v2.02022-08-10
CVE-2021-40040 [HIGH] CVE-2021-40040: Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploit
Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-37006HIGHCVSS 7.5v2.0v2.12022-08-10
CVE-2022-37006 [HIGH] CWE-276 CVE-2022-37006: Permission control vulnerability in the network module. Successful exploitation of this vulnerabilit
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
nvd
CVE-2022-37008HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37008 [HIGH] CWE-345 CVE-2022-37008: The recovery module has a vulnerability of bypassing the verification of an update package before us
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
nvd
CVE-2022-37001HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37001 [HIGH] CVE-2022-37001: The diag-router module has a vulnerability in intercepting excessive long and short instructions. Su
The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.
nvd
CVE-2022-37005HIGHCVSS 7.5v2.02022-08-10
CVE-2022-37005 [HIGH] CWE-88 CVE-2022-37005: The Settings application has an argument injection vulnerability. Successful exploitation of this vu
The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40034HIGHCVSS 7.5v2.02022-08-10
CVE-2021-40034 [HIGH] CVE-2021-40034: The video framework has the memory overwriting vulnerability caused by addition overflow. Successful
The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2021-40030HIGHCVSS 7.5v2.02022-08-10
CVE-2021-40030 [HIGH] CVE-2021-40030: The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affe
The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-34737CRITICALCVSS 9.1v2.02022-07-12
CVE-2022-34737 [CRITICAL] CWE-276 CVE-2022-34737: The application security module has a vulnerability in permission assignment. Successful exploitatio
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
nvd
CVE-2022-34735HIGHCVSS 7.5v2.02022-07-12
CVE-2022-34735 [HIGH] CWE-476 CVE-2022-34735: The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
nvd
CVE-2021-40012HIGHCVSS 7.5v2.02022-07-12
CVE-2021-40012 [HIGH] CVE-2021-40012: Vulnerability of pointers being incorrectly used during data transmission in the video framework. Su
Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
nvd