Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 5 of 56
CVE-2023-44105P3CRITICALCVSS 9.8v2.0.0v2.0.1+4 more2023-10-11
CVE-2023-44105 [CRITICAL] CWE-269 CVE-2023-44105: Vulnerability of permissions not being strictly verified in the window management module.Successful
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
CVE-2024-56439P3HIGHCVSS 7.5v5.0.02025-01-08
CVE-2024-56439 [HIGH] CWE-311 CVE-2024-56439: Access control vulnerability in the identity authentication module Impact: Successful exploitation o
Access control vulnerability in the identity authentication module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37011P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-07
CVE-2021-37011 [CRITICAL] CWE-787 CVE-2021-37011: There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.
nvd
CVE-2021-37064P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-07
CVE-2021-37064 [CRITICAL] CWE-22 CVE-2021-37064: There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smart
There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to arbitrary file created.
nvd
CVE-2022-31760P3CRITICALCVSS 9.1v2.02022-06-13
CVE-2022-31760 [CRITICAL] CVE-2022-31760: Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
nvd
CVE-2022-41581P3CRITICALCVSS 9.1v2.02022-10-14
CVE-2022-41581 [CRITICAL] CWE-125 CVE-2022-41581: The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation o
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
nvd
CVE-2023-39398P3CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39398 [CRITICAL] CWE-275 CVE-2023-39398: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-39399P3CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39399 [CRITICAL] CWE-275 CVE-2023-39399: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-39403P3CRITICALCVSS 9.1v2.0.0v2.0.1+3 more2023-08-13
CVE-2023-39403 [CRITICAL] CWE-358 CVE-2023-39403: Parameter verification vulnerability in the installd module. Successful exploitation of this vulnera
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
nvd
CVE-2023-52106P3CRITICALCVSS 9.1v4.0.0v3.1.02024-01-16
CVE-2023-52106 [CRITICAL] CWE-264 CVE-2023-52106: Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Succes
Vulnerability of permission verification for APIs in the DownloadProviderMain module.
Impact: Successful exploitation of this vulnerability will affect integrity and availability.
nvd
CVE-2025-54627P3HIGHCVSS 8.8v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54627 [HIGH] CWE-787 CVE-2025-54627: Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulner
Out-of-bounds write vulnerability in the skia module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37054P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-08
CVE-2021-37054 [HIGH] CWE-287 CVE-2021-37054: There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successfu
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-22434P3CRITICALCVSS 9.8v2.02022-02-25
CVE-2021-22434 [CRITICAL] CWE-119 CVE-2021-22434: There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of thi
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
nvd
CVE-2021-37084P3CRITICALCVSS 9.8fixed in 2.0v2.02021-12-07
CVE-2021-37084 [CRITICAL] CWE-20 CVE-2021-37084: There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of t
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious invoking other functions of the Smart Assistant through text messages.
nvd
CVE-2021-46786P3CRITICALCVSS 9.8v2.02022-05-13
CVE-2021-46786 [CRITICAL] CWE-119 CVE-2021-46786: The audio module has a vulnerability in verifying the parameters passed by the application space.Suc
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
nvd
CVE-2022-48288P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-02-09
CVE-2022-48288 [HIGH] CWE-306 CVE-2022-48288: The bundle management module lacks authentication and control mechanisms in some APIs. Successful ex
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2022-48289P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-02-09
CVE-2022-48289 [HIGH] CWE-306 CVE-2022-48289: The bundle management module lacks authentication and control mechanisms in some APIs. Successful ex
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40017P3CRITICALCVSS 9.8v2.02022-09-16
CVE-2021-40017 [CRITICAL] CWE-20 CVE-2021-40017: The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.
nvd
CVE-2023-52361P3HIGHCVSS 7.5v4.0.02024-02-18
CVE-2023-52361 [HIGH] CWE-863 CVE-2023-52361: The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploita
The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.
nvd
CVE-2022-41578P3CRITICALCVSS 9.8v2.0v2.12022-10-14
CVE-2022-41578 [CRITICAL] CWE-787 CVE-2022-41578: The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerabil
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.
nvd