VendorsHuaweiharmonyos2.0
Vulnerabilities

Huawei Harmonyos 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

271CVEs
CVE-2021-46742
The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
Published 2022-04-11 · Modified
9.1EPSS 0.007
CVE-2021-40053
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
Published 2022-03-07 · Modified
9.1EPSS 0.007
CVE-2022-22260
The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.
Published 2022-05-13 · Modified
9.1EPSS 0.007
CVE-2022-31760
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
Published 2022-06-13 · Modified
9.1EPSS 0.007
CVE-2022-39008
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.
Published 2022-09-16 · Modified
9.1EPSS 0.006
CVE-2021-39982
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.
Published 2022-01-03 · Modified
9.1EPSS 0.006
CVE-2022-34737
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
Published 2022-07-11 · Modified
9.1EPSS 0.006
CVE-2022-38986
The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.
Published 2022-10-14 · Modified
9.1EPSS 0.006
CVE-2023-37245
Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
Published 2023-07-06 · Modified
9.1EPSS 0.005
CVE-2022-48349
The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability.
Published 2023-03-27 · Modified
9.1EPSS 0.005
CVE-2021-46840
The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.1EPSS 0.005
CVE-2022-41581
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.1EPSS 0.005
CVE-2021-46839
The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.1EPSS 0.005
CVE-2022-48312
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
Published 2023-04-16 · Modified
9.1EPSS 0.004
CVE-2021-22376
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.
Published 2021-06-30 · Modified
8.4EPSS 0.002
CVE-2021-40064
There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stability.
Published 2022-03-07 · Modified
7.8EPSS 0.008
CVE-2021-40048
There is an incorrect buffer size calculation vulnerability in the video framework. Successful exploitation of this vulnerability will affect availability.
Published 2022-03-07 · Modified
7.8EPSS 0.008
CVE-2021-40052
There is an incorrect buffer size calculation vulnerability in the video framework.Successful exploitation of this vulnerability may affect availability.
Published 2022-03-07 · Modified
7.8EPSS 0.008
CVE-2021-37026
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2022-34735
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
Published 2022-07-11 · Modified
7.8EPSS 0.007
CVE-2022-34736
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
Published 2022-07-11 · Modified
7.8EPSS 0.007
CVE-2021-37024
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37025
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37003
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37004
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37005
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37007
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37008
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37012
There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37015
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37017
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37018
There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37019
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2022-22252
The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability.
Published 2022-05-13 · Modified
7.8EPSS 0.007
CVE-2021-40047
There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
Published 2022-03-07 · Modified
7.8EPSS 0.006
CVE-2022-41576
The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2023-26547
The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2023-03-27 · Modified
7.8EPSS 0.002
CVE-2021-22416
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22458
A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.
Published 2021-10-28 · Modified
7.8EPSS 0.002
CVE-2021-22422
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published 2021-08-03 · Modified
7.8EPSS 0.002
← Prev2 / 7Next →