VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2022-44546
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44547
The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44550
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44552
The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2023-39396
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.
Published 2023-08-13 · Modified
7.5EPSS 0.005
CVE-2021-46852
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44556
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
Published 2022-11-08 · Modified
7.5EPSS 0.005
CVE-2023-46758
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
Published 2023-11-08 · Modified
7.5EPSS 0.005
CVE-2022-48351
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48352
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48356
The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48357
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48346
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-39011
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-44554
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44555
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-38981
The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-38984
The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-38985
The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-38998
The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-41586
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-48359
The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48606
Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.
Published 2023-09-26 · Modified
7.5EPSS 0.005
CVE-2023-37239
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program.
Published 2023-07-06 · Modified
7.5EPSS 0.005
CVE-2023-41299
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
Published 2023-09-25 · Modified
7.5EPSS 0.005
CVE-2023-41300
Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
Published 2023-09-25 · Modified
7.5EPSS 0.005
CVE-2023-39409
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
Published 2023-09-25 · Modified
7.5EPSS 0.005
CVE-2022-46317
The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
Published 2022-12-20 · Modified
7.5EPSS 0.004
CVE-2022-46322
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
Published 2022-12-20 · Modified
7.5EPSS 0.004
CVE-2023-39408
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
Published 2023-09-25 · Modified
7.5EPSS 0.004
CVE-2023-39404
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2023-39390
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2023-39389
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2022-48517
Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2023-39382
Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2023-39395
Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2023-34164
Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation of this vulnerability may affect availability.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2023-39406
Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2023-37241
Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2023-39397
Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.
Published 2023-08-13 · Modified
7.5EPSS 0.004
← Prev11 / 27Next →