Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39389 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | ||
| CVE-2023-39388 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | ||
| CVE-2023-39384 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-39383 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security. | ||
| CVE-2023-39382 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart. | ||
| CVE-2023-39381 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-39380 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. | ||
| CVE-2023-37241 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-37239 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program. | ||
| CVE-2023-34164 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-1695 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-1691 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2022-48520 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48519 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48517 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-48516 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality. | ||
| CVE-2022-48515 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2022-48514 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48508 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2022-48507 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality. |
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this vulnerability may affect service integrity.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality.
Page 18 of 54