VendorsHuaweiharmonyosall versions
Vulnerabilities

Huawei Harmonyos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1050CVEs
CVE-2021-37015
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37017
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37018
There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37019
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37004
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37024
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2021-37025
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.
Published 2021-11-23 · Modified
7.8EPSS 0.007
CVE-2022-22252
The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability.
Published 2022-05-13 · Modified
7.8EPSS 0.007
CVE-2021-37077
There is a NULL Pointer Dereference vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel crash.
Published 2021-12-07 · Modified
7.8EPSS 0.007
CVE-2021-37057
There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to restart the phone.
Published 2021-12-07 · Modified
7.8EPSS 0.007
CVE-2021-37089
There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel restart.
Published 2021-12-07 · Modified
7.8EPSS 0.007
CVE-2021-40047
There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
Published 2022-03-07 · Modified
7.8EPSS 0.006
CVE-2024-56447
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-01-08 · Analyzed
7.8EPSS 0.003
CVE-2022-41576
The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2023-26547
The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2023-03-27 · Modified
7.8EPSS 0.002
CVE-2021-22416
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22458
A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.
Published 2021-10-28 · Modified
7.8EPSS 0.002
CVE-2021-22423
A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22418
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22420
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22422
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2021-22425
A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2022-31762
The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-06-13 · Modified
7.8EPSS 0.002
CVE-2021-22451
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
Published 2021-10-28 · Modified
7.8EPSS 0.002
CVE-2021-22470
A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.
Published 2021-10-28 · Modified
7.8EPSS 0.002
CVE-2021-22421
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.
Published 2021-08-03 · Modified
7.8EPSS 0.002
CVE-2022-41585
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2022-41584
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.
Published 2022-10-14 · Modified
7.8EPSS 0.002
CVE-2021-37000
Some Huawei wearables have a permission management vulnerability.
Published 2024-12-28 · Analyzed
7.8EPSS 0.001
CVE-2025-46584
Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-05-06 · Analyzed
7.8EPSS 0.001
CVE-2025-48903
Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-06-06 · Analyzed
7.8EPSS 0.001
CVE-2025-31172
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-04-07 · Analyzed
7.8EPSS 0.001
CVE-2024-36500
Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2024-06-14 · Modified
7.8EPSS 0.001
CVE-2025-58287
Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-10-11 · Analyzed
7.8EPSS 0.001
CVE-2025-68968
Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.
Published 2026-01-14 · Analyzed
7.8EPSS 0.001
CVE-2023-52365
Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2024-02-18 · Modified
7.7EPSS 0.003
CVE-2025-54607
Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-08-06 · Analyzed
7.7EPSS 0.003
CVE-2026-34853
Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-04-13 · Analyzed
7.7EPSS 0.002
CVE-2024-57960
Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-02-06 · Analyzed
7.7EPSS 0.002
CVE-2023-52713
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2024-04-07 · Analyzed
7.7EPSS 0.001
← Prev6 / 27Next →