VendorsHuaweiharmonyos2.0
Vulnerabilities

Huawei Harmonyos 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

271CVEs
CVE-2022-48301
The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.
Published 2023-02-09 · Modified
7.5EPSS 0.003
CVE-2022-48295
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).
Published 2023-02-09 · Modified
7.5EPSS 0.003
CVE-2022-22253
The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability.
Published 2022-04-11 · Modified
7.5EPSS 0.003
CVE-2022-37008
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
Published 2022-08-09 · Modified
7.5EPSS 0.003
CVE-2021-40055
There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.
Published 2022-03-07 · Modified
7.1EPSS 0.005
CVE-2021-22469
A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.
Published 2021-10-28 · Modified
7.1EPSS 0.002
CVE-2021-22326
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.
Published 2021-06-30 · Modified
7.1EPSS 0.002
CVE-2022-41577
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.
Published 2022-10-14 · Modified
7.1EPSS 0.001
CVE-2021-37023
There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause media files which can be reads and writes in non-distributed directories on any device on the network..
Published 2021-11-23 · Modified
6.5EPSS 0.006
CVE-2022-34740
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
Published 2022-07-11 · Modified
6.5EPSS 0.003
CVE-2022-34741
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
Published 2022-07-11 · Modified
6.5EPSS 0.003
CVE-2022-48354
The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
Published 2023-03-27 · Modified
6.5EPSS 0.002
CVE-2022-48292
The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
6.5EPSS 0.002
CVE-2022-48293
The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2023-02-09 · Modified
6.5EPSS 0.002
CVE-2022-48314
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-04-16 · Modified
6.5EPSS 0.002
CVE-2022-48313
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
Published 2023-04-16 · Modified
6.5EPSS 0.002
CVE-2022-39006
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
Published 2022-09-16 · Modified
5.9EPSS 0.004
CVE-2022-44563
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-11-09 · Modified
5.9EPSS 0.003
CVE-2021-22296
A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system.
Published 2021-03-02 · Modified
5.5EPSS 0.002
CVE-2022-31751
The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2021-22463
A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2022-31756
The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2021-22467
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2021-22452
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2021-22456
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2022-31755
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2022-31763
The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.002
CVE-2021-22465
A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
Published 2021-10-28 · Modified
5.5EPSS 0.002
CVE-2021-22424
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.
Published 2021-08-03 · Modified
5.5EPSS 0.001
CVE-2021-22459
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2022-31759
AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability.
Published 2022-06-13 · Modified
5.5EPSS 0.001
CVE-2021-22318
A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service.
Published 2021-07-14 · Modified
5.5EPSS 0.001
CVE-2021-22461
A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22462
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22466
A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22417
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.
Published 2021-08-03 · Modified
5.5EPSS 0.001
CVE-2021-22471
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22450
A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22454
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
Published 2021-10-28 · Modified
5.5EPSS 0.001
CVE-2021-22455
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released.
Published 2021-10-28 · Modified
5.5EPSS 0.001
← Prev6 / 7Next →