Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41303 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2023 | Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified. | ||
| CVE-2023-41302 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-41301 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-41300 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2023-41293 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-41299 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2023-41298 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-39409 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2023-39408 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2023-39406 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart. | ||
| CVE-2023-39404 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-39397 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-39395 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-39394 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified. | ||
| CVE-2023-39391 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-39390 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-39386 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart. | ||
| CVE-2023-39396 | Hig | 0.49 | 7.5 | 0.01 | Aug 13, 2023 | Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-39393 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten. | ||
| CVE-2023-39392 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten. |
- risk 0.49cvss 7.5epss 0.01
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.
- risk 0.49cvss 7.5epss 0.00
Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.00
Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.00
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.
- risk 0.49cvss 7.5epss 0.01
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.
Page 17 of 54