VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2024-57959
Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2025-02-06 · Analyzed
9.8EPSS 0.002
CVE-2026-28536
Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2026-03-05 · Analyzed
9.6EPSS 0.003
CVE-2021-37011
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.
Published 2021-12-07 · Modified
9.4EPSS 0.009
CVE-2021-37074
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.
Published 2021-12-08 · Modified
9.3EPSS 0.006
CVE-2024-42037
Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-08-08 · Analyzed
9.3EPSS 0.001
CVE-2024-39671
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-07-25 · Modified
9.3EPSS 0.001
CVE-2025-64314
Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability may affect confidentiality.
Published 2025-11-28 · Analyzed
9.3EPSS 0.001
CVE-2021-22394
There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration.
Published 2022-02-25 · Modified
9.1EPSS 0.008
CVE-2021-37087
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create arbitrary file.
Published 2021-12-07 · Modified
9.1EPSS 0.008
CVE-2021-37088
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can write any content to any file.
Published 2021-12-07 · Modified
9.1EPSS 0.008
CVE-2021-37064
There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to arbitrary file created.
Published 2021-12-07 · Modified
9.1EPSS 0.008
CVE-2021-37016
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.
Published 2021-11-23 · Modified
9.1EPSS 0.008
CVE-2021-37021
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.
Published 2021-12-07 · Modified
9.1EPSS 0.008
CVE-2021-37099
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file.
Published 2021-12-07 · Modified
9.1EPSS 0.008
CVE-2021-37051
There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
Published 2021-12-08 · Modified
9.1EPSS 0.008
CVE-2021-37020
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.
Published 2021-12-07 · Modified
9.1EPSS 0.008
CVE-2021-37065
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted.
Published 2021-12-07 · Modified
9.1EPSS 0.007
CVE-2021-37116
PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.
Published 2022-01-03 · Modified
9.1EPSS 0.007
CVE-2021-37062
There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory overflow and information leakage.
Published 2021-12-07 · Modified
9.1EPSS 0.007
CVE-2021-46742
The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
Published 2022-04-11 · Modified
9.1EPSS 0.007
CVE-2021-40053
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
Published 2022-03-07 · Modified
9.1EPSS 0.007
CVE-2021-37079
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission.
Published 2021-12-07 · Modified
9.1EPSS 0.007
CVE-2022-22260
The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.
Published 2022-05-13 · Modified
9.1EPSS 0.007
CVE-2022-31760
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
Published 2022-06-13 · Modified
9.1EPSS 0.007
CVE-2022-39008
The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.
Published 2022-09-16 · Modified
9.1EPSS 0.006
CVE-2022-34737
The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
Published 2022-07-11 · Modified
9.1EPSS 0.006
CVE-2021-39982
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.
Published 2022-01-03 · Modified
9.1EPSS 0.006
CVE-2022-38986
The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.
Published 2022-10-14 · Modified
9.1EPSS 0.006
CVE-2024-45443
Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2024-09-04 · Analyzed
9.1EPSS 0.005
CVE-2023-37245
Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
Published 2023-07-06 · Modified
9.1EPSS 0.005
CVE-2023-37240
Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read.
Published 2023-07-06 · Modified
9.1EPSS 0.005
CVE-2022-48349
The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability.
Published 2023-03-27 · Modified
9.1EPSS 0.005
CVE-2023-39400
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Published 2023-08-13 · Modified
9.1EPSS 0.005
CVE-2023-39401
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Published 2023-08-13 · Modified
9.1EPSS 0.005
CVE-2023-39402
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Published 2023-08-13 · Modified
9.1EPSS 0.005
CVE-2021-46839
The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.1EPSS 0.005
CVE-2022-41581
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.1EPSS 0.005
CVE-2021-46840
The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.1EPSS 0.005
CVE-2021-46895
Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.
Published 2023-08-13 · Modified
9.1EPSS 0.005
CVE-2023-3455
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
Published 2023-07-05 · Modified
9.1EPSS 0.004
← Prev3 / 27Next →