VendorsHuaweiharmonyos4.3.0
Vulnerabilities

Huawei Harmonyos 4.3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2024-57959
Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2025-02-06 · Analyzed
9.8EPSS 0.002
CVE-2024-57958
Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Published 2025-02-06 · Analyzed
9.1EPSS 0.002
CVE-2025-31170
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2024-58127
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2024-58126
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2024-58125
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Published 2025-04-07 · Analyzed
9.1EPSS 0.002
CVE-2024-58044
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-03-04 · Analyzed
8.4EPSS 0.001
CVE-2025-58302
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-11-28 · Analyzed
8.4EPSS 0.001
CVE-2026-34853
Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-04-13 · Analyzed
7.7EPSS 0.002
CVE-2024-57960
Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-02-06 · Analyzed
7.7EPSS 0.002
CVE-2026-28552
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-03-05 · Analyzed
7.5EPSS 0.004
CVE-2025-54630
:Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-08-06 · Analyzed
7.5EPSS 0.002
CVE-2025-54628
Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-08-06 · Analyzed
7.5EPSS 0.002
CVE-2026-28553
Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2026-04-13 · Analyzed
7.5EPSS 0.002
CVE-2024-58043
Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-03-04 · Analyzed
7.3EPSS 0.001
CVE-2025-54611
EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-08-06 · Analyzed
7.3EPSS 0.001
CVE-2026-34859
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
7.1EPSS 0.001
CVE-2026-34854
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
7.1EPSS 0.001
CVE-2025-58314
Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2025-11-28 · Analyzed
7.1EPSS 0.001
CVE-2025-58311
UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2025-11-28 · Analyzed
7.1EPSS 0.001
CVE-2025-58276
Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-09-05 · Analyzed
6.8EPSS 0.001
CVE-2025-54629
Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
Published 2025-08-06 · Analyzed
6.7EPSS 0.001
CVE-2025-48902
Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-06-06 · Analyzed
6.6EPSS 0.001
CVE-2026-24917
UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
6.5EPSS 0.001
CVE-2026-24920
Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
6.2EPSS 0.001
CVE-2025-68959
Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2026-01-14 · Analyzed
6.2EPSS 0.001
CVE-2025-53186
Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-07-07 · Analyzed
6.2EPSS 0.001
CVE-2025-66325
Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2025-12-08 · Analyzed
6.2EPSS 0.001
CVE-2025-68970
Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published 2026-01-14 · Analyzed
6.1EPSS 0.001
CVE-2026-24919
Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
6.0EPSS 0.001
CVE-2026-34855
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Published 2026-04-13 · Analyzed
5.7EPSS 0.001
CVE-2025-48910
Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-06-06 · Analyzed
5.5EPSS 0.002
CVE-2026-24927
Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2026-02-06 · Analyzed
5.5EPSS 0.001
CVE-2025-66329
Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.
Published 2025-12-08 · Modified
5.5EPSS 0.001
CVE-2025-54646
Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.
Published 2025-08-06 · Analyzed
5.1EPSS 0.001
CVE-2025-53178
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.
Published 2025-07-07 · Analyzed
4.8EPSS 0.001
CVE-2025-53177
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.
Published 2025-07-07 · Analyzed
3.9EPSS 0.001