cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 49 of 56
CVE-2025-46593P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2025-46593 [MEDIUM] CWE-400 CVE-2025-46593: Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploit Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-46592P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2025-46592 [MEDIUM] CWE-476 CVE-2025-46592: Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54638P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54638 [MEDIUM] CWE-502 CVE-2025-54638: Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of the ad service.
nvd
CVE-2026-24917P4MEDIUMCVSS 5.5v3.1.0v4.0.0+2 more2026-02-06
CVE-2026-24917 [MEDIUM] CWE-416 CVE-2026-24917: UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-46586P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2025-46586 [MEDIUM] CWE-862 CVE-2025-46586: Permission control vulnerability in the contacts module Impact: Successful exploitation of this vuln Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-68964P4MEDIUMCVSS 5.5v5.0.1v5.1.0+2 more2026-01-14
CVE-2025-68964 [MEDIUM] CWE-20 CVE-2025-68964: Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulner Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58299P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58299 [MEDIUM] CWE-416 CVE-2025-58299: Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58281P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-09-05
CVE-2025-58281 [MEDIUM] CWE-125 CVE-2025-58281: Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58298P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58298 [MEDIUM] CWE-121 CVE-2025-58298: Data processing error vulnerability in the package management module. Successful exploitation of thi Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58312P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-58312 [MEDIUM] CWE-264 CVE-2025-58312: Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vul Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-66323P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-12-08
CVE-2025-66323 [MEDIUM] CWE-358 CVE-2025-66323: Vulnerability of improper criterion security check in the card module. Impact: Successful exploitati Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-41984P4MEDIUMCVSS 5.2v6.1.02026-06-09
CVE-2026-41984 [MEDIUM] CWE-284 CVE-2026-41984: UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2026-58552P4MEDIUMCVSS 5.1v6.1.02026-07-15
CVE-2026-58552 [MEDIUM] CWE-120 CVE-2026-58552: Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-58551P4MEDIUMCVSS 5.1v6.1.02026-07-15
CVE-2026-58551 [MEDIUM] CWE-120 CVE-2026-58551: Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41985P4MEDIUMCVSS 5.1v6.1.02026-06-09
CVE-2026-41985 [MEDIUM] CWE-284 CVE-2026-41985: UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2025-53178P4MEDIUMCVSS 4.8v4.0.0v4.2.0+1 more2025-07-07
CVE-2025-53178 [MEDIUM] CWE-264 CVE-2025-53178: Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of th Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.
nvd
CVE-2025-66327P4MEDIUMCVSS 4.7v5.0.1v5.1.02025-12-08
CVE-2025-66327 [MEDIUM] CWE-362 CVE-2025-66327: Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerab Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52380P4MEDIUMCVSS 4.3v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52380 [MEDIUM] CVE-2023-52380: Vulnerability of improper access control in the email module.Successful exploitation of this vulnera Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-31763P4MEDIUMCVSS 5.5v2.02022-06-13
CVE-2022-31763 [MEDIUM] CWE-476 CVE-2022-31763: The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitat The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2021-22461P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22461 [MEDIUM] CWE-770 CVE-2021-22461: A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerabilit A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
nvd
Huawei Harmonyos vulnerabilities | cvebase