VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2025-68963
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2026-01-14 · Analyzed
5.7EPSS 0.001
CVE-2025-68967
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2026-01-14 · Analyzed
5.7EPSS 0.001
CVE-2024-51521
Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2024-11-05 · Analyzed
5.7EPSS 0.001
CVE-2026-34855
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
5.7EPSS 0.001
CVE-2024-32993
Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-05-11 · Analyzed
5.6EPSS 0.001
CVE-2024-36501
Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.
Published 2024-06-14 · Modified
5.6EPSS 0.001
CVE-2024-47291
Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2024-09-27 · Analyzed
5.6EPSS 0.001
CVE-2026-34867
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-04-13 · Analyzed
5.6EPSS 0.001
CVE-2021-22296
A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system.
Published 2021-03-02 · Modified
5.5EPSS 0.002
CVE-2022-31751
The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2023-49248
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
Published 2023-12-06 · Modified
5.5EPSS 0.002
CVE-2021-40037
There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.
Published 2022-01-07 · Modified
5.5EPSS 0.002
CVE-2021-22478
The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage.
Published 2022-02-25 · Modified
5.5EPSS 0.002
CVE-2021-22463
A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2022-31756
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2021-22452
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2021-22467
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2025-48910
Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-06-06 · Analyzed
5.5EPSS 0.002
CVE-2021-22456
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2022-31755
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2021-40045
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2022-02-09 · Modified
5.5EPSS 0.002
CVE-2022-31763
The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2021-22479
The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.
Published 2022-02-25 · Modified
5.5EPSS 0.002
CVE-2021-22441
Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.
Published 2022-02-25 · Modified
5.5EPSS 0.002
CVE-2021-22465
A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2022-31759
AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.001
CVE-2021-22318
A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service.
Published 2021-07-14 · Modified
5.5EPSS 0.001
CVE-2021-22417
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.
Published 2021-08-03 · Modified
5.5EPSS 0.001
CVE-2021-22424
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.
Published 2021-08-03 · Modified
5.5EPSS 0.001
CVE-2021-22450
A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22454
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22455
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22459
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22461
A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22462
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22466
A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22471
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2023-52383
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-05-11 · Analyzed
5.5EPSS 0.001
CVE-2023-52384
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.
Published 2024-05-11 · Analyzed
5.5EPSS 0.001
CVE-2021-22295
A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.
Published 2021-08-06 · Modified
5.5EPSS 0.001
← Prev22 / 27Next →