VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2021-40050
There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.
Published 2022-03-07 · Modified
10.0EPSS 0.011
CVE-2021-39979
HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.
Published 2022-01-03 · Modified
10.0EPSS 0.011
CVE-2021-37022
There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.
Published 2021-11-23 · Modified
10.0EPSS 0.010
CVE-2021-37045
There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the kernel-mode code to be executed.
Published 2021-12-08 · Modified
10.0EPSS 0.009
CVE-2021-22429
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
10.0EPSS 0.009
CVE-2021-22432
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
Published 2022-02-25 · Modified
10.0EPSS 0.009
CVE-2026-34865
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
10.0EPSS 0.004
CVE-2023-34157
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
Published 2023-06-16 · Modified
10.0EPSS 0.004
CVE-2021-37095
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution.
Published 2021-12-07 · Modified
9.8EPSS 0.014
CVE-2021-40010
The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution.
Published 2022-01-07 · Modified
9.8EPSS 0.012
CVE-2021-40036
The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.
Published 2022-06-13 · Modified
9.8EPSS 0.010
CVE-2022-22258
The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.
Published 2022-04-11 · Modified
9.8EPSS 0.010
CVE-2021-22434
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-37128
HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.
Published 2022-01-03 · Modified
9.8EPSS 0.009
CVE-2021-22426
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-22433
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-37049
There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may rewrite the memory of adjacent objects.
Published 2021-12-08 · Modified
9.8EPSS 0.009
CVE-2021-22430
There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-39996
There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.
Published 2022-01-07 · Modified
9.8EPSS 0.008
CVE-2021-37040
There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting.
Published 2021-12-08 · Modified
9.8EPSS 0.008
CVE-2021-22431
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
Published 2022-02-25 · Modified
9.8EPSS 0.008
CVE-2021-39990
The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.
Published 2022-01-03 · Modified
9.8EPSS 0.008
CVE-2021-46786
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
Published 2022-05-13 · Modified
9.8EPSS 0.008
CVE-2022-29794
The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.
Published 2022-05-13 · Modified
9.8EPSS 0.008
CVE-2021-37084
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious invoking other functions of the Smart Assistant through text messages.
Published 2021-12-07 · Modified
9.8EPSS 0.007
CVE-2021-22480
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.
Published 2022-02-25 · Modified
9.8EPSS 0.007
CVE-2021-37059
There is a Weaknesses Introduced During Design
Published 2021-12-07 · Modified
9.8EPSS 0.007
CVE-2021-37063
There is a Cryptographic Issues vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to read and delete images of Harmony devices.
Published 2021-12-07 · Modified
9.8EPSS 0.007
CVE-2022-39007
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-09-16 · Modified
9.8EPSS 0.007
CVE-2022-39009
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.
Published 2022-09-16 · Modified
9.8EPSS 0.007
CVE-2022-38983
The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2021-40017
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-39002
Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-39000
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-38999
The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-44562
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-11-09 · Modified
9.8EPSS 0.006
CVE-2022-44559
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-11-09 · Modified
9.8EPSS 0.006
CVE-2022-44558
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-11-09 · Modified
9.8EPSS 0.006
CVE-2022-38982
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2022-41580
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.8EPSS 0.006
1 / 27Next →