VendorsHuaweiharmonyos2.0
Vulnerabilities

Huawei Harmonyos 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

271CVEs
CVE-2022-44546
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44552
The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-41591
The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized access to other system files.
Published 2022-12-20 · Modified
7.5EPSS 0.005
CVE-2022-44550
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2021-46852
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44556
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
Published 2022-11-08 · Modified
7.5EPSS 0.005
CVE-2022-48357
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48352
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48356
The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48351
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-48346
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-39011
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-44555
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-44554
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
Published 2022-11-09 · Modified
7.5EPSS 0.005
CVE-2022-48359
The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-03-27 · Modified
7.5EPSS 0.005
CVE-2022-38981
The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-38984
The HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-38985
The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-38998
The HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability will cause out-of-bounds read, which affects data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2022-41586
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-10-14 · Modified
7.5EPSS 0.005
CVE-2023-1696
The multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.
Published 2023-05-20 · Modified
7.5EPSS 0.004
CVE-2022-44549
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
Published 2022-11-09 · Modified
7.5EPSS 0.004
CVE-2022-44557
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-11-09 · Modified
7.5EPSS 0.004
CVE-2023-26549
The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-03-27 · Modified
7.5EPSS 0.004
CVE-2022-48294
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-48299
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-48300
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-38977
The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.
Published 2022-10-14 · Modified
7.5EPSS 0.004
CVE-2022-41583
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.
Published 2022-10-14 · Modified
7.5EPSS 0.004
CVE-2022-48298
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-48297
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-48286
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2022-48302
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2023-1692
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-05-20 · Modified
7.5EPSS 0.004
CVE-2022-44561
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
Published 2022-11-09 · Modified
7.5EPSS 0.004
CVE-2022-48287
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
Published 2023-02-09 · Modified
7.5EPSS 0.004
CVE-2021-46893
Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vulnerability may affect integrity.
Published 2023-07-05 · Modified
7.5EPSS 0.003
CVE-2023-44109
Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.003
CVE-2023-44093
Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vulnerability may affect service confidentiality.
Published 2023-10-11 · Modified
7.5EPSS 0.003
CVE-2022-41588
The home screen module has a vulnerability in service logic processing.Successful exploitation of this vulnerability may affect data integrity.
Published 2022-10-14 · Modified
7.5EPSS 0.003
← Prev5 / 7Next →