cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 52 of 56
CVE-2021-22424P4MEDIUMCVSS 5.5v2.02021-08-03
CVE-2021-22424 [MEDIUM] CWE-401 CVE-2021-22424: A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.
nvd
CVE-2021-22471P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22471 [MEDIUM] CWE-476 CVE-2021-22471: A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may explo A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
nvd
CVE-2021-22462P4MEDIUMCVSS 5.5v2.02021-10-28
CVE-2021-22462 [MEDIUM] CWE-476 CVE-2021-22462: A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may explo A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
nvd
CVE-2026-58557P4MEDIUMCVSS 4.8v6.1.02026-07-15
CVE-2026-58557 [MEDIUM] CWE-701 CVE-2026-58557: Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerabilit Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-54122P4MEDIUMCVSS 4.7v5.0.02024-12-12
CVE-2024-54122 [MEDIUM] CWE-362 CVE-2024-54122: Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of th Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-51515P4MEDIUMCVSS 4.7v5.0.02024-11-05
CVE-2024-51515 [MEDIUM] CWE-362 CVE-2024-51515: Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vul Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28550P4MEDIUMCVSS 4.7v6.0.02026-03-05
CVE-2026-28550 [MEDIUM] CWE-840 CVE-2026-28550: Race condition vulnerability in the security control module. Impact: Successful exploitation of this Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34849P4MEDIUMCVSS 4.7v5.1.0v6.0.02026-04-13
CVE-2026-34849 [MEDIUM] CWE-362 CVE-2026-34849: UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerabi UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-58296P4MEDIUMCVSS 4.7v5.0.1v5.1.02025-09-05
CVE-2025-58296 [MEDIUM] CWE-362 CVE-2025-58296: Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerabil Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect function stability.
nvd
CVE-2026-34861P4MEDIUMCVSS 4.7v6.0.02026-04-13
CVE-2026-34861 [MEDIUM] CWE-362 CVE-2026-34861: Race condition vulnerability in the thermal management module. Impact: Successful exploitation of th Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28549P4MEDIUMCVSS 4.7v6.0.0v5.1.02026-03-05
CVE-2026-28549 [MEDIUM] CWE-362 CVE-2026-28549: Race condition vulnerability in the permission management service. Impact: Successful exploitation o Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-66328P4MEDIUMCVSS 4.7v5.0.12025-12-08
CVE-2025-66328 [MEDIUM] CWE-362 CVE-2025-66328: Multi-thread race condition vulnerability in the network management module. Impact: Successful explo Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28551P4MEDIUMCVSS 4.7v5.1.0v6.0.02026-03-05
CVE-2026-28551 [MEDIUM] CWE-362 CVE-2026-28551: Race condition vulnerability in the device security management module. Impact: Successful exploitati Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-54632P4MEDIUMCVSS 4.6v4.3.1v5.0.1+1 more2025-08-06
CVE-2025-54632 [MEDIUM] CWE-120 CVE-2025-54632: Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploit Vulnerability of insufficient data length verification in the HVB module. Impact: Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2025-54633P4MEDIUMCVSS 4.4v5.0.1v5.1.02025-08-06
CVE-2025-54633 [MEDIUM] CWE-125 CVE-2025-54633: Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful Out-of-bounds read vulnerability in the register configuration of the DMA module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41978P4MEDIUMCVSS 4.4v6.1.0v6.0.02026-06-09
CVE-2026-41978 [MEDIUM] CWE-275 CVE-2026-41978: Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulner Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-44110P4MEDIUMCVSS 4.3v2.0.1v3.0.0+2 more2023-10-11
CVE-2023-44110 [MEDIUM] CWE-20 CVE-2023-44110: Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-22318P4MEDIUMCVSS 5.5v2.0vHarmonyOS 2.02021-07-14
CVE-2021-22318 [MEDIUM] CWE-476 CVE-2021-22318: A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may e A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service.
nvd
CVE-2021-40015P4MEDIUMCVSS 4.7fixed in 2.0v4.0.0+3 more2022-02-09
CVE-2021-40015 [MEDIUM] CWE-362 CVE-2021-40015: There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful expl There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vulnerability may affect kernel stability.
nvd
CVE-2025-68957P4MEDIUMCVSS 4.7v6.0.02026-01-14
CVE-2025-68957 [MEDIUM] CWE-362 CVE-2025-68957: Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitat Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
Huawei Harmonyos vulnerabilities | cvebase