VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2022-41578
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2022-38980
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2024-32991
Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-05-11 · Analyzed
9.8EPSS 0.006
CVE-2023-46773
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2023-12-06 · Modified
9.8EPSS 0.005
CVE-2021-46851
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
Published 2022-11-09 · Modified
9.8EPSS 0.005
CVE-2022-37002
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
Published 2022-08-09 · Modified
9.8EPSS 0.005
CVE-2022-46316
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2022-37003
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
Published 2022-08-09 · Modified
9.8EPSS 0.005
CVE-2023-39405
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.
Published 2023-08-13 · Modified
9.8EPSS 0.005
CVE-2022-48511
Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.
Published 2023-07-06 · Modified
9.8EPSS 0.005
CVE-2022-46319
Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2022-46323
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2022-46326
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2022-46325
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2022-48510
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.
Published 2023-07-06 · Modified
9.8EPSS 0.005
CVE-2022-46324
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2022-46320
The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2022-48512
Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.
Published 2023-07-06 · Modified
9.8EPSS 0.005
CVE-2022-48353
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions.
Published 2023-03-27 · Modified
9.8EPSS 0.005
CVE-2022-48479
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
Published 2023-05-26 · Modified
9.8EPSS 0.005
CVE-2022-48478
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
Published 2023-05-26 · Modified
9.8EPSS 0.005
CVE-2023-52378
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2024-02-18 · Modified
9.8EPSS 0.005
CVE-2023-52370
Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.
Published 2024-02-18 · Analyzed
9.8EPSS 0.005
CVE-2023-52103
Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.
Published 2024-01-16 · Modified
9.8EPSS 0.005
CVE-2022-48513
Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.
Published 2023-07-06 · Modified
9.8EPSS 0.005
CVE-2023-37242
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
Published 2023-07-06 · Modified
9.8EPSS 0.005
CVE-2021-46891
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Published 2023-07-05 · Modified
9.8EPSS 0.005
CVE-2021-46890
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Published 2023-07-05 · Modified
9.8EPSS 0.005
CVE-2021-46894
Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.
Published 2023-07-06 · Modified
9.8EPSS 0.005
CVE-2022-44551
The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
Published 2022-11-09 · Modified
9.8EPSS 0.005
CVE-2022-46327
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.
Published 2022-12-20 · Modified
9.8EPSS 0.005
CVE-2023-52381
Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Published 2024-02-18 · Analyzed
9.8EPSS 0.004
CVE-2023-41297
Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
Published 2023-09-25 · Modified
9.8EPSS 0.004
CVE-2022-48605
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
Published 2023-09-25 · Modified
9.8EPSS 0.004
CVE-2023-44105
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-10-11 · Modified
9.8EPSS 0.004
CVE-2023-44106
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-10-11 · Modified
9.8EPSS 0.004
CVE-2023-41294
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
Published 2023-09-25 · Modified
9.8EPSS 0.004
CVE-2023-44116
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.
Published 2023-10-11 · Modified
9.8EPSS 0.004
CVE-2025-54617
Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.
Published 2025-08-06 · Analyzed
9.8EPSS 0.003
CVE-2024-57961
Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2025-02-06 · Analyzed
9.8EPSS 0.003
← Prev2 / 27Next →