Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 45 of 56
CVE-2023-52543P4MEDIUMCVSS 6.2v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52543 [MEDIUM] CWE-269 CVE-2023-52543: Permission verification vulnerability in the system module. Impact: Successful exploitation of this
Permission verification vulnerability in the system module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2025-53186P4MEDIUMCVSS 6.2v2.0.0v2.1.0+5 more2025-07-07
CVE-2025-53186 [MEDIUM] CWE-264 CVE-2025-53186: Vulnerability that allows third-party call apps to send broadcasts without verification in the audio
Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-37085P4MEDIUMCVSS 5.9fixed in 2.0v2.02021-12-07
CVE-2021-37085 [MEDIUM] CWE-362 CVE-2021-37085: There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulner
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.
nvd
CVE-2026-34867P4MEDIUMCVSS 5.6v5.1.0v6.0.02026-04-13
CVE-2026-34867 [MEDIUM] CWE-415 CVE-2026-34867: Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vu
Double free vulnerability in the multi-mode input system.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24918P4MEDIUMCVSS 5.5v4.3.1v5.1.0+2 more2026-02-06
CVE-2026-24918 [MEDIUM] CWE-476 CVE-2026-24918: Address read vulnerability in the communication module. Impact: Successful exploitation of this vuln
Address read vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51512P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51512 [MEDIUM] CWE-20 CVE-2024-51512: Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploi
Vulnerability of parameter type not being verified in the WantAgent module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51511P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51511 [MEDIUM] CWE-20 CVE-2024-51511: Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploi
Vulnerability of parameter type not being verified in the WantAgent module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-56450P4MEDIUMCVSS 5.5v4.0.0v4.2.02025-01-08
CVE-2024-56450 [MEDIUM] CWE-120 CVE-2024-56450: Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this
Buffer overflow vulnerability in the component driver module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-7271P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-07-25
CVE-2023-7271 [MEDIUM] CWE-840 CVE-2023-7271: Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnera
Privilege escalation vulnerability in the NMS module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2025-54620P4MEDIUMCVSS 5.5v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54620 [MEDIUM] CWE-502 CVE-2025-54620: Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitati
Deserialization vulnerability of untrusted data in the ability module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24926P4MEDIUMCVSS 5.5v6.0.02026-02-06
CVE-2026-24926 [MEDIUM] CWE-787 CVE-2026-24926: Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vuln
Out-of-bounds write vulnerability in the camera module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24920P4MEDIUMCVSS 5.5v4.2.0v4.3.0+1 more2026-02-06
CVE-2026-24920 [MEDIUM] CWE-264 CVE-2026-24920: Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerab
Permission control vulnerability in the AMS module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54642P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2025-08-06
CVE-2025-54642 [MEDIUM] CWE-20 CVE-2025-54642: Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Im
Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54641P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2025-08-06
CVE-2025-54641 [MEDIUM] CWE-20 CVE-2025-54641: Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module.
Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-39674P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-07-25
CVE-2024-39674 [MEDIUM] CWE-312 CVE-2024-39674: Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulner
Plaintext vulnerability in the Gallery search module.
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2025-54636P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2025-08-06
CVE-2025-54636 [MEDIUM] CWE-20 CVE-2025-54636: Issue of buffer overflow caused by insufficient data verification in the kernel drop detection modul
Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54645P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54645 [MEDIUM] CWE-129 CVE-2025-54645: Out-of-bounds array access issue due to insufficient data verification in the location service modul
Out-of-bounds array access issue due to insufficient data verification in the location service module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24925P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-02-06
CVE-2026-24925 [MEDIUM] CWE-122 CVE-2026-24925: Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of thi
Heap-based buffer overflow vulnerability in the image module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34863P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-04-13
CVE-2026-34863 [MEDIUM] CWE-787 CVE-2026-34863: Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulner
Out-of-bounds write vulnerability in the file system.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28542P4MEDIUMCVSS 5.5v3.1.0v4.0.0+1 more2026-03-05
CVE-2026-28542 [MEDIUM] CWE-755 CVE-2026-28542: Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of
Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.
nvd