VendorsHuaweiharmonyos2.1
Vulnerabilities

Huawei Harmonyos 2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2022-48302
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-48287
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-41588
The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity.
Published 2022-10-14 · Modified
7.5EPSS 0.003
CVE-2022-41577
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.
Published 2022-10-14 · Modified
7.1EPSS 0.001
CVE-2022-48313
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-04-16 · Modified
6.5EPSS 0.002
CVE-2022-48314
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-04-16 · Modified
6.5EPSS 0.002
CVE-2022-39006
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
Published 2022-09-16 · Modified
5.9EPSS 0.004
CVE-2022-44563
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-11-09 · Modified
5.9EPSS 0.003
CVE-2022-44553
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
Published 2022-11-09 · Modified
5.3EPSS 0.003
CVE-2023-3456
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-07-06 · Modified
5.3EPSS 0.003
CVE-2022-48296
The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices.
Published 2023-02-09 · Modified
5.3EPSS 0.003
CVE-2023-34165
Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.
Published 2023-06-16 · Modified
5.3EPSS 0.003
CVE-2022-44548
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.
Published 2022-11-09 · Modified
4.3EPSS 0.002
← Prev2 / 2