cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 8 of 56
CVE-2023-44118P3CRITICALCVSS 9.1v2.0.0v3.0.02023-10-11
CVE-2023-44118 [CRITICAL] CWE-284 CVE-2023-44118: Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnera Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
nvd
CVE-2021-46895P3CRITICALCVSS 9.1v2.0.02023-08-13
CVE-2021-46895 [CRITICAL] CWE-701 CVE-2021-46895: Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successfu Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.
nvd
CVE-2023-52101P3CRITICALCVSS 9.1v2.0.0v2.1.0+3 more2024-01-16
CVE-2023-52101 [CRITICAL] CWE-200 CVE-2023-52101: Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.
nvd
CVE-2023-52538P3CRITICALCVSS 9.1v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52538 [CRITICAL] CWE-347 CVE-2023-52538: Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful ex Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2026-41964P3HIGHCVSS 8.4v6.1.0v6.0.02026-05-15
CVE-2026-41964 [HIGH] CWE-362 CVE-2026-41964: Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability m Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
nvd
CVE-2021-37100P3HIGHCVSS 7.5fixed in 2.0v2.02021-12-07
CVE-2021-37100 [HIGH] CWE-287 CVE-2021-37100: There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of thi There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.
nvd
CVE-2022-22254P3HIGHCVSS 7.5v2.02022-04-11
CVE-2022-22254 [HIGH] CVE-2022-22254: A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-22395P3HIGHCVSS 7.5v2.02022-02-25
CVE-2021-22395 [HIGH] CWE-94 CVE-2021-22395: There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerabilit There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-41303P3HIGHCVSS 7.5v2.0.0v2.0.1+3 more2023-09-25
CVE-2023-41303 [HIGH] CWE-20 CVE-2023-41303: Command injection vulnerability in the distributed file system module. Successful exploitation of th Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.
nvd
CVE-2021-22480P3CRITICALCVSS 9.8fixed in 2.0v2.02022-02-25
CVE-2021-22480 [CRITICAL] CWE-190 CVE-2021-22480: The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploi The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.
nvd
CVE-2021-37063P3CRITICALCVSS 9.8fixed in 2.0v2.02021-12-07
CVE-2021-37063 [CRITICAL] CVE-2021-37063: There is a Cryptographic Issues vulnerability in Huawei Smartphone.Successful exploitation of this v There is a Cryptographic Issues vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to read and delete images of Harmony devices.
nvd
CVE-2023-49245P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49245 [HIGH] CVE-2023-49245: Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulner Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49243P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2023-12-06
CVE-2023-49243 [HIGH] CVE-2023-49243: Vulnerability of unauthorized access to email attachments in the email module. Successful exploitati Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49239P3HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49239 [HIGH] CWE-863 CVE-2023-49239: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-49246P3HIGHCVSS 7.5v2.0.0v3.0.0+2 more2023-12-06
CVE-2023-49246 [HIGH] CWE-863 CVE-2023-49246: Unauthorized access vulnerability in the card management module. Successful exploitation of this vul Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-44549P3HIGHCVSS 7.5v2.0v2.12022-11-09
CVE-2022-44549 [HIGH] CWE-862 CVE-2022-44549: The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnera The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
nvd
CVE-2022-44557P3HIGHCVSS 7.5v2.0v2.1+1 more2022-11-09
CVE-2022-44557 [HIGH] CWE-276 CVE-2022-44557: The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2023-52540P3HIGHCVSS 7.5v2.0.0v2.1.0+3 more2024-04-08
CVE-2023-52540 [HIGH] CWE-287 CVE-2023-52540: Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of th Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.
nvd
CVE-2024-42031P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-08-08
CVE-2024-42031 [HIGH] CWE-16 CVE-2024-42031: Access permission verification vulnerability in the Settings module. Impact: Successful exploitation Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-54100P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2024-12-12
CVE-2024-54100 [HIGH] CWE-20 CVE-2024-54100: Vulnerability of improper access control in the secure input module Impact: Successful exploitation Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
nvd
Huawei Harmonyos vulnerabilities | cvebase