Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 49 of 56
CVE-2025-46593P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2025-46593 [MEDIUM] CWE-400 CVE-2025-46593: Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploit
Process residence vulnerability in abnormal scenarios in the print module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-46592P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2025-46592 [MEDIUM] CWE-476 CVE-2025-46592: Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation
Null pointer dereference vulnerability in the USB HDI driver module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54638P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54638 [MEDIUM] CWE-502 CVE-2025-54638: Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of
Issue of inconsistent read/write serialization in the ad module.
Impact: Successful exploitation of this vulnerability may affect the availability of the ad service.
nvd
CVE-2026-24917P4MEDIUMCVSS 5.5v3.1.0v4.0.0+2 more2026-02-06
CVE-2026-24917 [MEDIUM] CWE-416 CVE-2026-24917: UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may
UAF vulnerability in the security module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-46586P4MEDIUMCVSS 5.5v5.0.02025-05-06
CVE-2025-46586 [MEDIUM] CWE-862 CVE-2025-46586: Permission control vulnerability in the contacts module Impact: Successful exploitation of this vuln
Permission control vulnerability in the contacts module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-68964P4MEDIUMCVSS 5.5v5.0.1v5.1.0+2 more2026-01-14
CVE-2025-68964 [MEDIUM] CWE-20 CVE-2025-68964: Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulner
Data verification vulnerability in the HiView module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58299P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58299 [MEDIUM] CWE-416 CVE-2025-58299: Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this
Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58281P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-09-05
CVE-2025-58281 [MEDIUM] CWE-125 CVE-2025-58281: Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation
Out-of-bounds read vulnerability in the runtime interpreter module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58298P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58298 [MEDIUM] CWE-121 CVE-2025-58298: Data processing error vulnerability in the package management module. Successful exploitation of thi
Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58312P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-58312 [MEDIUM] CWE-264 CVE-2025-58312: Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vul
Permission control vulnerability in the App Lock module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-66323P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-12-08
CVE-2025-66323 [MEDIUM] CWE-358 CVE-2025-66323: Vulnerability of improper criterion security check in the card module. Impact: Successful exploitati
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-41984P4MEDIUMCVSS 5.2v6.1.02026-06-09
CVE-2026-41984 [MEDIUM] CWE-284 CVE-2026-41984: UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2026-58552P4MEDIUMCVSS 5.1v6.1.02026-07-15
CVE-2026-58552 [MEDIUM] CWE-120 CVE-2026-58552: Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-58551P4MEDIUMCVSS 5.1v6.1.02026-07-15
CVE-2026-58551 [MEDIUM] CWE-120 CVE-2026-58551: Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41985P4MEDIUMCVSS 5.1v6.1.02026-06-09
CVE-2026-41985 [MEDIUM] CWE-284 CVE-2026-41985: UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2025-53178P4MEDIUMCVSS 4.8v4.0.0v4.2.0+1 more2025-07-07
CVE-2025-53178 [MEDIUM] CWE-264 CVE-2025-53178: Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of th
Permission bypass vulnerability in the calendar storage module
Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.
nvd
CVE-2025-66327P4MEDIUMCVSS 4.7v5.0.1v5.1.02025-12-08
CVE-2025-66327 [MEDIUM] CWE-362 CVE-2025-66327: Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerab
Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52380P4MEDIUMCVSS 4.3v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52380 [MEDIUM] CVE-2023-52380: Vulnerability of improper access control in the email module.Successful exploitation of this vulnera
Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-31763P4MEDIUMCVSS 5.5v2.02022-06-13
CVE-2022-31763 [MEDIUM] CWE-476 CVE-2022-31763: The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitat
The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.
nvd
CVE-2021-22461P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22461 [MEDIUM] CWE-770 CVE-2021-22461: A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerabilit
A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
nvd