Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 50 of 56
CVE-2021-22450P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22450 [MEDIUM] CWE-459 CVE-2021-22450: A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit thi
A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.
nvd
CVE-2024-51513P4MEDIUMCVSS 5.5v5.0.02024-11-05
CVE-2024-51513 [MEDIUM] CWE-400 CVE-2024-51513: Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitat
Vulnerability of processes not being fully terminated in the VPN module
Impact: Successful exploitation of this vulnerability will affect power consumption.
nvd
CVE-2024-45445P4MEDIUMCVSS 5.5v3.0.0v3.1.0+2 more2024-09-04
CVE-2024-45445 [MEDIUM] CWE-459 CVE-2024-45445: Vulnerability of resources not being closed or released in the keystore module Impact: Successful ex
Vulnerability of resources not being closed or released in the keystore module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-56451P4MEDIUMCVSS 5.5v5.0.02025-01-08
CVE-2024-56451 [MEDIUM] CWE-680 CVE-2024-56451: Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful
Integer overflow vulnerability during glTF model loading in the 3D engine module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58286P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58286 [MEDIUM] CWE-25 CVE-2025-58286: Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnera
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58292P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58292 [MEDIUM] CWE-27 CVE-2025-58292: Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnera
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58290P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58290 [MEDIUM] CWE-41 CVE-2025-58290: Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnera
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58291P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58291 [MEDIUM] CWE-29 CVE-2025-58291: Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnera
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54634P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-08-06
CVE-2025-54634 [MEDIUM] CWE-755 CVE-2025-54634: Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Success
Vulnerability of improper processing of abnormal conditions in huge page separation.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-53170P4MEDIUMCVSS 5.5v5.1.02025-07-07
CVE-2025-53170 [MEDIUM] CWE-476 CVE-2025-53170: Null pointer dereference vulnerability in the application exit cause module Impact: Successful explo
Null pointer dereference vulnerability in the application exit cause module
Impact: Successful exploitation of this vulnerability may affect function stability.
nvd
CVE-2025-58276P4MEDIUMCVSS 5.5v2.0.0v3.0.0+5 more2025-09-05
CVE-2025-58276 [MEDIUM] CWE-264 CVE-2025-58276: Permission verification vulnerability in the home screen module Impact: Successful exploitation of t
Permission verification vulnerability in the home screen module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58288P4MEDIUMCVSS 5.5v5.0.1v5.1.02025-10-11
CVE-2025-58288 [MEDIUM] CWE-275 CVE-2025-58288: Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnera
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58307P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-58307 [MEDIUM] CWE-416 CVE-2025-58307: UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this
UAF vulnerability in the screen recording framework module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58303P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-58303 [MEDIUM] CWE-362 CVE-2025-58303: UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this
UAF vulnerability in the screen recording framework module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34857P4MEDIUMCVSS 5.5v5.1.0v5.1.1+1 more2026-04-13
CVE-2026-34857 [MEDIUM] CWE-362 CVE-2026-34857: UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28537P4MEDIUMCVSS 5.5v6.0.02026-03-05
CVE-2026-28537 [MEDIUM] CWE-415 CVE-2026-28537: Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerabilit
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58316P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-58316 [MEDIUM] CWE-362 CVE-2025-58316: DoS vulnerability in the video-related system service module. Impact: Successful exploitation of thi
DoS vulnerability in the video-related system service module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-64313P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-64313 [MEDIUM] CWE-362 CVE-2025-64313: Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this
Denial of service (DoS) vulnerability in the office service.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-24930P4MEDIUMCVSS 5.5v5.1.0v6.0.02026-02-06
CVE-2026-24930 [MEDIUM] CWE-362 CVE-2026-24930: UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulner
UAF concurrency vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-66332P4MEDIUMCVSS 5.5v5.0.1v5.1.0+1 more2025-12-08
CVE-2025-66332 [MEDIUM] CWE-494 CVE-2025-66332: Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.
nvd