Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 47 of 56
CVE-2025-54631P4MEDIUMCVSS 5.5v5.0.1v5.0.2+5 more2025-08-06
CVE-2025-54631 [MEDIUM] CWE-190 CVE-2025-54631: Vulnerability of insufficient data length verification in the partition module. Impact: Successful e
Vulnerability of insufficient data length verification in the partition module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28541P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-03-05
CVE-2026-28541 [MEDIUM] CWE-264 CVE-2026-28541: Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of thi
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-66329P4MEDIUMCVSS 5.5v2.0.0v3.0.0+5 more2025-12-08
CVE-2025-66329 [MEDIUM] CWE-264 CVE-2025-66329: Permission control vulnerability in the window management module. Impact: Successful exploitation of
Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34864P4MEDIUMCVSS 5.5v6.0.02026-04-13
CVE-2026-34864 [MEDIUM] CWE-119 CVE-2026-34864: Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of
Boundary-unlimited vulnerability in the application read module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28538P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-03-05
CVE-2026-28538 [MEDIUM] CWE-24 CVE-2026-28538: Path traversal vulnerability in the certificate management module. Impact: Successful exploitation o
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34866P4MEDIUMCVSS 5.1v6.0.02026-04-13
CVE-2026-34866 [MEDIUM] CWE-120 CVE-2026-34866: Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerab
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2022-48355P4MEDIUMCVSS 6.5v2.0.0v2.1.0+2 more2023-03-27
CVE-2022-48355 [MEDIUM] CWE-787 CVE-2022-48355: The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vu
The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
nvd
CVE-2021-22296P4MEDIUMCVSS 5.5v2.0vHarmonyOS 2.02021-03-02
CVE-2021-22296 [MEDIUM] CVE-2021-22296: A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability
A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system.
nvd
CVE-2021-40037P4MEDIUMCVSS 5.5fixed in 2.0v2.02022-01-10
CVE-2021-40037 [MEDIUM] CWE-843 CVE-2021-40037: There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the M
There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.
nvd
CVE-2022-31755P4MEDIUMCVSS 5.5v2.02022-06-13
CVE-2022-31755 [MEDIUM] CWE-281 CVE-2022-31755: The communication module has a vulnerability of improper permission preservation. Successful exploit
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2021-22456P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22456 [MEDIUM] CVE-2021-22456: A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
nvd
CVE-2021-22479P4MEDIUMCVSS 5.5fixed in 2.0v2.02022-02-25
CVE-2021-22479 [MEDIUM] CWE-119 CVE-2021-22479: The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful
The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.
nvd
CVE-2021-22417P4MEDIUMCVSS 5.5v2.02021-08-03
CVE-2021-22417 [MEDIUM] CVE-2021-22417: A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.
nvd
CVE-2021-22465P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22465 [MEDIUM] CWE-787 CVE-2021-22465: A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exp
A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
nvd
CVE-2023-52383P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2024-05-14
CVE-2023-52383 [MEDIUM] CWE-415 CVE-2023-52383: Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability w
Double-free vulnerability in the RSMC module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-52384P4MEDIUMCVSS 5.5v3.0.0v3.1.0+1 more2024-05-14
CVE-2023-52384 [MEDIUM] CWE-415 CVE-2023-52384: Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability w
Double-free vulnerability in the RSMC module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2021-22466P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22466 [MEDIUM] CWE-416 CVE-2021-22466: A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vu
A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
nvd
CVE-2021-22454P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22454 [MEDIUM] CWE-668 CVE-2021-22454: A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
nvd
CVE-2021-22455P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22455 [MEDIUM] CWE-190 CVE-2021-22455: A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released.
nvd
CVE-2024-56452P4MEDIUMCVSS 5.5v5.0.02025-01-08
CVE-2024-56452 [MEDIUM] CWE-120 CVE-2024-56452: Vulnerability of input parameters not being verified during glTF model loading in the 3D engine modu
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd