VendorsHuaweiharmonyos2.0
Vulnerabilities

Huawei Harmonyos 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

271CVEs
CVE-2022-31762
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-06-13 · Modified
7.8EPSS 0.002
CVE-2021-22418
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22420
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22470
A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.
Published 2021-10-28 · Modified
7.8EPSS 0.002
CVE-2021-22451
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published 2021-10-28 · Modified
7.8EPSS 0.002
CVE-2021-22421
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2022-41585
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-41584
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-29793
There is a configuration defect in the activation lock of mobile phones.Successful exploitation of this vulnerability may affect application availability.
Published 2022-05-13 · Modified
7.5EPSS 0.009
CVE-2022-39001
The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure.
Published 2022-09-16 · Modified
7.5EPSS 0.009
CVE-2021-40012
Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
Published 2022-07-11 · Modified
7.5EPSS 0.008
CVE-2022-34742
The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-07-11 · Modified
7.5EPSS 0.008
CVE-2021-40065
The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-04-11 · Modified
7.5EPSS 0.008
CVE-2021-40011
There is an uncontrolled resource consumption vulnerability in the display module. Successful exploitation of this vulnerability may affect integrity.
Published 2022-01-07 · Modified
7.5EPSS 0.008
CVE-2021-40049
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
Published 2022-03-07 · Modified
7.5EPSS 0.008
CVE-2021-46741
The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of this vulnerability may affect system integrity.
Published 2022-07-11 · Modified
7.5EPSS 0.008
CVE-2021-46740
The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-04-11 · Modified
7.5EPSS 0.008
CVE-2021-40051
There is an unauthorized access vulnerability in system components. Successful exploitation of this vulnerability will affect confidentiality.
Published 2022-03-07 · Modified
7.5EPSS 0.008
CVE-2021-46787
The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2021-40063
There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentiality.
Published 2022-03-07 · Modified
7.5EPSS 0.007
CVE-2022-22254
A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-04-11 · Modified
7.5EPSS 0.007
CVE-2022-22256
The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-04-11 · Modified
7.5EPSS 0.007
CVE-2022-22255
The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability.
Published 2022-04-11 · Modified
7.5EPSS 0.007
CVE-2021-37009
There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
Published 2021-11-23 · Modified
7.5EPSS 0.007
CVE-2021-37010
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
Published 2021-11-23 · Modified
7.5EPSS 0.007
CVE-2021-22319
There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause integer overflows.
Published 2022-02-25 · Modified
7.5EPSS 0.007
CVE-2021-37113
There is a Privilege escalation vulnerability with the file system component in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2022-01-03 · Modified
7.5EPSS 0.007
CVE-2021-37133
There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2022-01-03 · Modified
7.5EPSS 0.007
CVE-2021-22395
There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.
Published 2022-02-25 · Modified
7.5EPSS 0.007
CVE-2021-22489
There is a DoS vulnerability in smartphones. Successful exploitation of this vulnerability may affect service availability.
Published 2022-02-25 · Modified
7.5EPSS 0.007
CVE-2022-34739
The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings.
Published 2022-07-11 · Modified
7.5EPSS 0.007
CVE-2022-34743
The AT commands of the USB port have an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
Published 2022-07-11 · Modified
7.5EPSS 0.007
CVE-2022-29792
The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2022-29791
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2022-29790
The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2022-29789
The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2022-22261
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2022-29795
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2022-29796
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
Published 2022-05-13 · Modified
7.5EPSS 0.007
CVE-2021-37006
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
Published 2021-11-23 · Modified
7.5EPSS 0.007
← Prev3 / 7Next →