Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34157 | Cri | 0.65 | 10.0 | 0.00 | Jun 16, 2023 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | ||
| CVE-2023-52381 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2024 | Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. | ||
| CVE-2023-52378 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2024 | Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-52370 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2024 | Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access. | ||
| CVE-2023-52103 | Cri | 0.64 | 9.8 | 0.00 | Jan 16, 2024 | Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read. | ||
| CVE-2023-46773 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2023 | Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2023-44116 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized. | ||
| CVE-2023-44105 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-44106 | Cri | 0.64 | 9.8 | 0.00 | Oct 11, 2023 | API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2022-48605 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. | ||
| CVE-2023-41297 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking. | ||
| CVE-2023-41294 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. | ||
| CVE-2023-39405 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2023 | Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges. | ||
| CVE-2023-37242 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities. | ||
| CVE-2022-48513 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2022-48512 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally. | ||
| CVE-2022-48511 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally. | ||
| CVE-2022-48510 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations. | ||
| CVE-2021-46894 | Cri | 0.64 | 9.8 | 0.00 | Jul 6, 2023 | Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation. | ||
| CVE-2021-46891 | Cri | 0.64 | 9.8 | 0.00 | Jul 5, 2023 | Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. |
- risk 0.65cvss 10.0epss 0.00
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
- risk 0.64cvss 9.8epss 0.00
Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.
- risk 0.64cvss 9.8epss 0.00
Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.
- risk 0.64cvss 9.8epss 0.01
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
- risk 0.64cvss 9.8epss 0.00
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.64cvss 9.8epss 0.00
Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.
- risk 0.64cvss 9.8epss 0.00
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.
- risk 0.64cvss 9.8epss 0.00
Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.
- risk 0.64cvss 9.8epss 0.00
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
Page 1 of 54