VendorsHuaweiharmonyos2.0
Vulnerabilities

Huawei Harmonyos 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

271CVEs
CVE-2021-40050
There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.
Published 2022-03-07 · Modified
10.0EPSS 0.011
CVE-2021-37022
There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permission which can be escalated.
Published 2021-11-23 · Modified
10.0EPSS 0.010
CVE-2021-22429
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
10.0EPSS 0.009
CVE-2021-22432
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
Published 2022-02-25 · Modified
10.0EPSS 0.009
CVE-2021-40010
The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution.
Published 2022-01-07 · Modified
9.8EPSS 0.012
CVE-2022-22258
The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.
Published 2022-04-11 · Modified
9.8EPSS 0.010
CVE-2021-22434
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-22433
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-22426
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-22430
There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.
Published 2022-02-25 · Modified
9.8EPSS 0.009
CVE-2021-22431
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
Published 2022-02-25 · Modified
9.8EPSS 0.008
CVE-2021-46786
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
Published 2022-05-13 · Modified
9.8EPSS 0.008
CVE-2022-29794
The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.
Published 2022-05-13 · Modified
9.8EPSS 0.008
CVE-2022-39007
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-09-16 · Modified
9.8EPSS 0.007
CVE-2022-39009
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.
Published 2022-09-16 · Modified
9.8EPSS 0.007
CVE-2022-38983
The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2021-40017
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-39002
Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-39000
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-38999
The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
Published 2022-09-16 · Modified
9.8EPSS 0.006
CVE-2022-44559
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-11-09 · Modified
9.8EPSS 0.006
CVE-2022-44562
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-11-09 · Modified
9.8EPSS 0.006
CVE-2022-44558
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
Published 2022-11-09 · Modified
9.8EPSS 0.006
CVE-2022-38982
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2022-41578
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2022-41580
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2022-38980
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
Published 2022-10-14 · Modified
9.8EPSS 0.006
CVE-2021-46851
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
Published 2022-11-09 · Modified
9.8EPSS 0.005
CVE-2022-37002
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
Published 2022-08-09 · Modified
9.8EPSS 0.005
CVE-2022-37003
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
Published 2022-08-09 · Modified
9.8EPSS 0.005
CVE-2022-48353
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions.
Published 2023-03-27 · Modified
9.8EPSS 0.005
CVE-2022-48479
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
Published 2023-05-26 · Modified
9.8EPSS 0.005
CVE-2022-48478
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
Published 2023-05-26 · Modified
9.8EPSS 0.005
CVE-2021-46890
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Published 2023-07-05 · Modified
9.8EPSS 0.005
CVE-2023-37242
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
Published 2023-07-06 · Modified
9.8EPSS 0.005
CVE-2022-44551
The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
Published 2022-11-09 · Modified
9.8EPSS 0.005
CVE-2021-46891
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Published 2023-07-05 · Modified
9.8EPSS 0.005
CVE-2023-44106
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2023-10-11 · Modified
9.8EPSS 0.004
CVE-2021-22394
There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration.
Published 2022-02-25 · Modified
9.1EPSS 0.008
CVE-2021-37016
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause Information Disclosure or Denial of Service.
Published 2021-11-23 · Modified
9.1EPSS 0.008
1 / 7Next →