Huawei Harmonyos vulnerabilities
1,111 known vulnerabilities affecting huawei/harmonyos.
Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40
Vulnerabilities
Page 7 of 56
CVE-2022-22258P3CRITICALCVSS 9.8v2.02022-04-11
CVE-2022-22258 [CRITICAL] CVE-2022-22258: The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerabili
The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.
nvd
CVE-2021-22429P3CRITICALCVSS 9.8v2.02022-02-25
CVE-2021-22429 [CRITICAL] CWE-119 CVE-2021-22429: There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerabilit
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
nvd
CVE-2021-22426P3CRITICALCVSS 9.8v2.02022-02-25
CVE-2021-22426 [CRITICAL] CWE-119 CVE-2021-22426: There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerabilit
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
nvd
CVE-2021-22433P3CRITICALCVSS 9.8v2.02022-02-25
CVE-2021-22433 [CRITICAL] CWE-119 CVE-2021-22433: There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerabilit
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
nvd
CVE-2023-49241P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49241 [HIGH] CVE-2023-49241: API permission control vulnerability in the network management module. Successful exploitation of th
API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-48294P3HIGHCVSS 7.5v2.02023-02-09
CVE-2022-48294 [HIGH] CWE-287 CVE-2022-48294: The IHwAttestationService interface has a defect in authentication. Successful exploitation of this
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-52541P3HIGHCVSS 7.5v2.0.0v3.0.0+3 more2024-04-08
CVE-2023-52541 [HIGH] CWE-862 CVE-2023-52541: Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this
Authentication vulnerability in the API for app pre-loading.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-39009P3CRITICALCVSS 9.8v2.0v2.12022-09-16
CVE-2022-39009 [CRITICAL] CWE-287 CVE-2022-39009: The WLAN module has a vulnerability in permission verification. Successful exploitation of this vuln
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.
nvd
CVE-2022-38999P3CRITICALCVSS 9.8v2.02022-09-16
CVE-2022-38999 [CRITICAL] CVE-2022-38999: The AOD module has the improper update of reference count vulnerability. Successful exploitation of
The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
nvd
CVE-2022-38982P3CRITICALCVSS 9.8v2.02022-10-14
CVE-2022-38982 [CRITICAL] CWE-287 CVE-2022-38982: The fingerprint module has service logic errors.Successful exploitation of this vulnerability will c
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
nvd
CVE-2022-48511P3CRITICALCVSS 9.8v2.0.02023-07-06
CVE-2022-48511 [CRITICAL] CWE-843 CVE-2022-48511: Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successf
Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.
nvd
CVE-2022-48479P3CRITICALCVSS 9.8v2.0v2.0.02023-05-26
CVE-2022-48479 [CRITICAL] CWE-125 CVE-2022-48479: The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successf
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
nvd
CVE-2024-42039P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-09-04
CVE-2024-42039 [HIGH] CWE-285 CVE-2024-42039: Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerab
Access control vulnerability in the SystemUI module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-53167P3HIGHCVSS 7.5v5.0.1v5.1.02025-07-07
CVE-2025-53167 [HIGH] CWE-305 CVE-2025-53167: Authentication vulnerability in the distributed collaboration framework module Impact: Successful ex
Authentication vulnerability in the distributed collaboration framework module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-37002P3CRITICALCVSS 9.8v2.02022-08-10
CVE-2022-37002 [CRITICAL] CWE-269 CVE-2022-37002: The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulner
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
nvd
CVE-2024-54103P3HIGHCVSS 7.5v5.0.02024-12-12
CVE-2024-54103 [HIGH] CWE-264 CVE-2024-54103: Vulnerability of improper access control in the album module Impact: Successful exploitation of this
Vulnerability of improper access control in the album module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2025-64312P3HIGHCVSS 7.5v5.0.1v5.1.0+1 more2025-11-28
CVE-2025-64312 [HIGH] CWE-200 CVE-2025-64312: Permission control vulnerability in the file management module. Impact: Successful exploitation of t
Permission control vulnerability in the file management module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37099P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-07
CVE-2021-37099 [CRITICAL] CWE-22 CVE-2021-37099: There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnera
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file.
nvd
CVE-2023-3455P3CRITICALCVSS 9.1v3.0.0v3.1.02023-07-05
CVE-2023-3455 [CRITICAL] CWE-200 CVE-2023-3455: Key management vulnerability on system. Successful exploitation of this vulnerability may affect ser
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
nvd
CVE-2022-48348P3CRITICALCVSS 9.1v3.0.02023-03-27
CVE-2022-48348 [CRITICAL] CWE-200 CVE-2022-48348: The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of t
The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and integrity.
nvd