Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 54 of 56
CVE-2026-28544P4MEDIUMCVSS 4.7v6.0.02026-03-05
CVE-2026-28544 [MEDIUM] CWE-362 CVE-2026-28544: Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnera
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58045P4MEDIUMCVSS 4.7v5.0.02025-03-04
CVE-2024-58045 [MEDIUM] CWE-362 CVE-2024-58045: Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful
Multi-concurrency vulnerability in the media digital copyright protection module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2024-58048P4MEDIUMCVSS 4.7v5.0.02025-03-04
CVE-2024-58048 [MEDIUM] CWE-362 CVE-2024-58048: Multi-thread problem vulnerability in the package management module Impact: Successful exploitation
Multi-thread problem vulnerability in the package management module
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28545P4MEDIUMCVSS 4.7v6.0.02026-03-05
CVE-2026-28545 [MEDIUM] CWE-362 CVE-2026-28545: Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnera
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-28543P4MEDIUMCVSS 4.7v5.1.0v6.0.02026-03-05
CVE-2026-28543 [MEDIUM] CWE-362 CVE-2026-28543: Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitat
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-58553P4MEDIUMCVSS 4.0v6.1.02026-07-15
CVE-2026-58553 [MEDIUM] CWE-120 CVE-2026-58553: Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-58549P4MEDIUMCVSS 4.0v6.1.02026-07-15
CVE-2026-58549 [MEDIUM] CWE-120 CVE-2026-58549: Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-58550P4MEDIUMCVSS 4.0v6.1.02026-07-15
CVE-2026-58550 [MEDIUM] CWE-120 CVE-2026-58550: Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-58114P4MEDIUMCVSS 4.0v5.0.02025-06-06
CVE-2024-58114 [MEDIUM] CWE-770 CVE-2024-58114: Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploita
Resource allocation control failure vulnerability in the ArkUI framework
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2026-34858P4MEDIUMCVSS 4.1v5.1.0v5.1.1+1 more2026-04-13
CVE-2026-34858 [MEDIUM] CWE-362 CVE-2026-34858: UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2025-53177P4LOWCVSS 3.9v4.0.0v4.2.0+1 more2025-07-07
CVE-2025-53177 [LOW] CWE-264 CVE-2025-53177: Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of th
Permission bypass vulnerability in the calendar storage module
Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.
nvd
CVE-2026-41962P4LOWCVSS 3.6v6.1.0v6.0.02026-05-15
CVE-2026-41962 [LOW] CWE-264 CVE-2026-41962: Permission control vulnerability in the app management and control module. Impact: Successful exploi
Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-41974P4LOWCVSS 3.6v4.3.1v4.3.0+2 more2026-06-09
CVE-2026-41974 [LOW] CWE-264 CVE-2026-41974: Permission control vulnerability in service notifications. Impact: Successful exploitation of this v
Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2023-52720P4MEDIUMCVSS 4.1v3.0.0v3.1.0+1 more2024-05-14
CVE-2023-52720 [MEDIUM] CWE-362 CVE-2023-52720: Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vuln
Race condition vulnerability in the soundtrigger module
Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2023-41306P4LOWCVSS 3.7v2.0.0v2.0.12023-09-27
CVE-2023-41306 [LOW] CWE-362 CVE-2023-41306: Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful e
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.
nvd
CVE-2021-37073P4LOWCVSS 3.7fixed in 2.0v2.02021-12-07
CVE-2021-37073 [LOW] CWE-362 CVE-2021-37073: There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnera
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the detection result is tampered with.
nvd
CVE-2023-52371P4LOWCVSS 3.5v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52371 [LOW] CWE-476 CVE-2023-52371: Vulnerability of null references in the motor module.Successful exploitation of this vulnerability m
Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-22457P4LOWCVSS 3.3v2.02021-10-28
CVE-2021-22457 [LOW] CWE-20 CVE-2021-22457: A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may expl
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause out-of-bounds write.
nvd
CVE-2021-22294P4LOWCVSS 3.3v2.0vHarmonyOS 2.02021-03-02
CVE-2021-22294 [LOW] CVE-2021-22294: A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may expl
A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerability to issue commands repeatedly, exhausting system service resources.
nvd
CVE-2026-28540P4LOWCVSS 3.3v5.1.0v6.0.02026-03-05
CVE-2026-28540 [LOW] CWE-158 CVE-2026-28540: Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vul
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd