VendorsHuaweiharmonyos2.0.1
Vulnerabilities

Huawei Harmonyos 2.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

91CVEs
CVE-2022-48288
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-48289
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2023-39384
Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2023-39391
Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2022-48516
Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2023-39383
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
Published 2023-08-13 · Modified
7.5EPSS 0.004
CVE-2022-48606
Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.
Published 2023-09-26 · Modified
7.5EPSS 0.004
CVE-2023-44108
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-44095
Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-1695
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2023-1691
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2022-48507
Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2023-39408
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
Published 2023-09-25 · Modified
7.5EPSS 0.004
CVE-2023-39409
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
Published 2023-09-25 · Modified
7.5EPSS 0.004
CVE-2023-41300
Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
Published 2023-09-25 · Modified
7.5EPSS 0.004
CVE-2023-1692
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-05-20 · Modified
7.5EPSS 0.004
CVE-2022-48515
Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-07-06 · Modified
7.5EPSS 0.004
CVE-2023-41305
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-09-26 · Modified
7.5EPSS 0.004
CVE-2023-44111
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-44096
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-44097
Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-44100
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-44103
Out-of-bounds read vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-44104
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.004
CVE-2023-41301
Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-09-25 · Modified
7.5EPSS 0.004
CVE-2023-39394
Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.
Published 2023-08-13 · Modified
7.5EPSS 0.003
CVE-2023-44093
Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.003
CVE-2023-44109
Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.003
CVE-2023-41298
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-09-25 · Modified
7.5EPSS 0.003
CVE-2022-48508
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
Published 2023-07-06 · Modified
7.5EPSS 0.003
CVE-2023-44119
Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.
Published 2023-10-11 · Modified
7.5EPSS 0.003
CVE-2023-39392
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.
Published 2023-08-13 · Modified
7.5EPSS 0.002
CVE-2023-39393
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.
Published 2023-08-13 · Modified
7.5EPSS 0.002
CVE-2023-44098
Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-11-08 · Modified
7.5EPSS 0.002
CVE-2022-48291
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-03-27 · Modified
6.5EPSS 0.002
CVE-2022-48509
Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally.
Published 2023-07-06 · Modified
5.9EPSS 0.003
CVE-2022-48518
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
Published 2023-07-06 · Modified
5.5EPSS 0.001
CVE-2023-4565
Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be unavailable.
Published 2023-09-26 · Modified
5.3EPSS 0.005
CVE-2023-46755
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
Published 2023-11-08 · Modified
5.3EPSS 0.004
CVE-2023-41312
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
Published 2023-09-26 · Modified
5.3EPSS 0.004
← Prev2 / 3Next →