cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 45 of 56
CVE-2023-52543P4MEDIUMCVSS 6.2v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52543 [MEDIUM] CWE-269 CVE-2023-52543: Permission verification vulnerability in the system module. Impact: Successful exploitation of this Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2025-53186P4MEDIUMCVSS 6.2v2.0.0v2.1.0+5 more2025-07-07
CVE-2025-53186 [MEDIUM] CWE-264 CVE-2025-53186: Vulnerability that allows third-party call apps to send broadcasts without verification in the audio Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-37085P4MEDIUMCVSS 5.9fixed in 2.0v2.02021-12-07
CVE-2021-37085 [MEDIUM] CWE-362 CVE-2021-37085: There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulner There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.
nvd
CVE-2026-34867P4MEDIUMCVSS 5.6v5.1.0v6.0.02026-04-13
CVE-2026-34867 [MEDIUM] CWE-415 CVE-2026-34867: Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vu Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24918P4MEDIUMCVSS 5.5v4.3.1v5.1.0+2 more2026-02-06
CVE-2026-24918 [MEDIUM] CWE-476 CVE-2026-24918: Address read vulnerability in the communication module. Impact: Successful exploitation of this vuln Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51512P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51512 [MEDIUM] CWE-20 CVE-2024-51512: Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploi Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51511P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51511 [MEDIUM] CWE-20 CVE-2024-51511: Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploi Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-56450P4MEDIUMCVSS 5.5v4.0.0v4.2.02025-01-08
CVE-2024-56450 [MEDIUM] CWE-120 CVE-2024-56450: Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-7271P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-07-25
CVE-2023-7271 [MEDIUM] CWE-840 CVE-2023-7271: Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnera Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2025-54620P4MEDIUMCVSS 5.5v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54620 [MEDIUM] CWE-502 CVE-2025-54620: Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitati Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24926P4MEDIUMCVSS 5.5v6.0.02026-02-06
CVE-2026-24926 [MEDIUM] CWE-787 CVE-2026-24926: Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vuln Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24920P4MEDIUMCVSS 5.5v4.2.0v4.3.0+1 more2026-02-06
CVE-2026-24920 [MEDIUM] CWE-264 CVE-2026-24920: Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerab Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54642P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2025-08-06
CVE-2025-54642 [MEDIUM] CWE-20 CVE-2025-54642: Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Im Issue of buffer overflow caused by insufficient data verification in the kernel gyroscope module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54641P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2025-08-06
CVE-2025-54641 [MEDIUM] CWE-20 CVE-2025-54641: Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Issue of buffer overflow caused by insufficient data verification in the kernel acceleration module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-39674P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-07-25
CVE-2024-39674 [MEDIUM] CWE-312 CVE-2024-39674: Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulner Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2025-54636P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2025-08-06
CVE-2025-54636 [MEDIUM] CWE-20 CVE-2025-54636: Issue of buffer overflow caused by insufficient data verification in the kernel drop detection modul Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54645P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54645 [MEDIUM] CWE-129 CVE-2025-54645: Out-of-bounds array access issue due to insufficient data verification in the location service modul Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24925P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-02-06
CVE-2026-24925 [MEDIUM] CWE-122 CVE-2026-24925: Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of thi Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34863P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-04-13
CVE-2026-34863 [MEDIUM] CWE-787 CVE-2026-34863: Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulner Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28542P4MEDIUMCVSS 5.5v3.1.0v4.0.0+1 more2026-03-05
CVE-2026-28542 [MEDIUM] CWE-755 CVE-2026-28542: Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
Huawei Harmonyos vulnerabilities | cvebase