Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 48 of 56
CVE-2024-36502P4MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2024-06-14
CVE-2024-36502 [MEDIUM] CWE-125 CVE-2024-36502: Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnera
Out-of-bounds read vulnerability in the audio module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-51522P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51522 [MEDIUM] CWE-199 CVE-2024-51522: Vulnerability of improper device information processing in the device management module Impact: Succ
Vulnerability of improper device information processing in the device management module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24914P4MEDIUMCVSS 5.5v6.0.02026-02-06
CVE-2026-24914 [MEDIUM] CWE-416 CVE-2026-24914: Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerabi
Type confusion vulnerability in the camera module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51517P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51517 [MEDIUM] CWE-129 CVE-2024-51517: Vulnerability of improper memory access in the phone service module Impact: Successful exploitation
Vulnerability of improper memory access in the phone service module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51520P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51520 [MEDIUM] CWE-20 CVE-2024-51520: Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitati
Vulnerability of input parameters not being verified in the HDC module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-47291P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-09-27
CVE-2024-47291 [MEDIUM] CWE-16 CVE-2024-47291: Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation
Permission vulnerability in the ActivityManagerService (AMS) module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51519P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51519 [MEDIUM] CWE-20 CVE-2024-51519: Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitati
Vulnerability of input parameters not being verified in the HDC module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-5465P4MEDIUMCVSS 5.5v4.0.0v4.2.02024-06-14
CVE-2024-5465 [MEDIUM] CWE-264 CVE-2024-5465: Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerabilit
Function vulnerabilities in the Calendar module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-36503P4MEDIUMCVSS 5.5v2.0.0v2.1.0+3 more2024-06-14
CVE-2024-36503 [MEDIUM] CWE-908 CVE-2024-36503: Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulner
Memory management vulnerability in the Gralloc module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-51529P4MEDIUMCVSS 5.5v2.0.0v2.1.0+4 more2024-11-05
CVE-2024-51529 [MEDIUM] CWE-20 CVE-2024-51529: Data verification vulnerability in the battery module Impact: Successful exploitation of this vulne
Data verification vulnerability in the battery module
Impact: Successful exploitation of this vulnerability may affect function stability.
nvd
CVE-2024-56453P4MEDIUMCVSS 5.5v5.0.02025-01-08
CVE-2024-56453 [MEDIUM] CWE-120 CVE-2024-56453: Vulnerability of input parameters not being verified during glTF model loading in the 3D engine modu
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-56456P4MEDIUMCVSS 5.5v5.0.02025-01-08
CVE-2024-56456 [MEDIUM] CWE-120 CVE-2024-56456: Vulnerability of input parameters not being verified during glTF model loading in the 3D engine modu
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-56455P4MEDIUMCVSS 5.5v5.0.02025-01-08
CVE-2024-56455 [MEDIUM] CWE-120 CVE-2024-56455: Vulnerability of input parameters not being verified during glTF model loading in the 3D engine modu
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-56454P4MEDIUMCVSS 5.5v5.0.02025-01-08
CVE-2024-56454 [MEDIUM] CWE-120 CVE-2024-56454: Vulnerability of input parameters not being verified during glTF model loading in the 3D engine modu
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51521P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51521 [MEDIUM] CWE-269 CVE-2024-51521: Input parameter verification vulnerability in the background service module Impact: Successful explo
Input parameter verification vulnerability in the background service module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-22419P4MEDIUMCVSS 5.5v2.02021-08-03
CVE-2021-22419 [MEDIUM] CWE-345 CVE-2021-22419: A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Loc
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.
nvd
CVE-2025-54639P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54639 [MEDIUM] CWE-502 CVE-2025-54639: ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this v
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.
nvd
CVE-2025-54640P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54640 [MEDIUM] CWE-502 CVE-2025-54640: ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this v
ParcelMismatch vulnerability in attribute deserialization.
Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.
nvd
CVE-2025-58280P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-09-05
CVE-2025-58280 [MEDIUM] CWE-1321 CVE-2025-58280: Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitati
Vulnerability of exposing object heap addresses in the Ark eTS module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54614P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54614 [MEDIUM] CWE-20 CVE-2025-54614: Input verification vulnerability in the home screen module. Impact: Successful exploitation of this
Input verification vulnerability in the home screen module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd