cbcvebase.

Huawei Harmonyos vulnerabilities

1,111 known vulnerabilities affecting huawei/harmonyos.

Total CVEs
1,111
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL138HIGH539MEDIUM394LOW40

Vulnerabilities

Page 9 of 56
CVE-2024-57955P3HIGHCVSS 7.5v5.0.02025-02-06
CVE-2024-57955 [HIGH] CWE-787 CVE-2024-57955: Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnera Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2024-56449P3HIGHCVSS 7.5v2.0.0v2.1.0+4 more2025-01-08
CVE-2024-56449 [HIGH] CWE-840 CVE-2024-56449: Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vul Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2026-28553P3HIGHCVSS 7.5v4.0.0v4.2.0+2 more2026-04-13
CVE-2026-28553 [HIGH] CWE-275 CVE-2026-28553: Vulnerability of improper permission control in the theme setting module. Impact: Successful exploit Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2023-52377P3HIGHCVSS 7.4v2.0.0v2.1.0+3 more2024-02-18
CVE-2023-52377 [HIGH] CWE-120 CVE-2023-52377: Vulnerability of input data not being verified in the cellular data module.Successful exploitation o Vulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability may cause out-of-bounds access.
nvd
CVE-2025-54622P3HIGHCVSS 7.4v5.0.1v5.0.2+1 more2025-08-06
CVE-2025-54622 [HIGH] CWE-305 CVE-2025-54622: Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploita Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2021-37062P3CRITICALCVSS 9.1fixed in 2.0v2.02021-12-07
CVE-2021-37062 [CRITICAL] CWE-129 CVE-2021-37062: There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploita There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory overflow and information leakage.
nvd
CVE-2021-46742P3CRITICALCVSS 9.1v2.02022-04-11
CVE-2021-46742 [CRITICAL] CVE-2021-46742: The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secu The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
nvd
CVE-2022-22260P3CRITICALCVSS 9.1v2.02022-05-13
CVE-2022-22260 [CRITICAL] CWE-416 CVE-2022-22260: The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.
nvd
CVE-2021-40050P3CRITICALCVSS 9.8v2.02022-03-10
CVE-2021-40050 [CRITICAL] CWE-125 CVE-2021-40050: There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vul There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.
nvd
CVE-2022-22256P3HIGHCVSS 7.5v2.02022-04-11
CVE-2022-22256 [HIGH] CVE-2022-22256: The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-40005P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40005 [HIGH] CVE-2021-40005: The distributed data service component has a vulnerability in data access control. Successful exploi The distributed data service component has a vulnerability in data access control. Successful exploitation of this vulnerability may affect data confidentiality.
nvd
CVE-2021-37125P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-37125 [HIGH] CWE-200 CVE-2021-37125: Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Succe Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause confidentiality is affected.
nvd
CVE-2021-39971P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-03
CVE-2021-39971 [HIGH] CWE-668 CVE-2021-39971: Password vault has a External Control of System or Configuration Setting vulnerability.Successful ex Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
nvd
CVE-2021-40026P3HIGHCVSS 7.5fixed in 2.0v2.02022-01-10
CVE-2021-40026 [HIGH] CWE-787 CVE-2021-40026: There is a Heap-based buffer overflow vulnerability in the AOD module in smartphones. Successful exp There is a Heap-based buffer overflow vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
nvd
CVE-2022-41591P3HIGHCVSS 7.5v2.0v2.1+1 more2022-12-20
CVE-2022-41591 [HIGH] CWE-22 CVE-2022-41591: The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.
nvd
CVE-2023-37239P3HIGHCVSS 7.5v2.0.1v3.0.0+1 more2023-07-06
CVE-2023-37239 [HIGH] CWE-200 CVE-2023-37239: Format string vulnerability in the distributed file system. Attackers who bypass the selinux permis Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program.
nvd
CVE-2022-48519P3HIGHCVSS 7.5v2.0.0v2.0.12023-07-06
CVE-2022-48519 [HIGH] CWE-200 CVE-2022-48519: Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerabil Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2022-48520P3HIGHCVSS 7.5v2.0.0v2.0.12023-07-06
CVE-2022-48520 [HIGH] CWE-200 CVE-2022-48520: Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerabil Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
nvd
CVE-2023-44115P3HIGHCVSS 7.5v2.0.0v2.0.1+4 more2023-11-08
CVE-2023-44115 [HIGH] CWE-200 CVE-2023-44115: Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
nvd
CVE-2022-39011P3HIGHCVSS 7.5v2.02022-10-14
CVE-2022-39011 [HIGH] CWE-693 CVE-2022-39011: The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel spa The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.
nvd
Huawei Harmonyos vulnerabilities | cvebase