Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1693 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2023 | The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-1692 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2023 | The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-26549 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-26548 | Hig | 0.49 | 7.5 | 0.01 | Mar 27, 2023 | The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2022-48360 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48359 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48357 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel. | ||
| CVE-2022-48356 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition. | ||
| CVE-2022-48352 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic. | ||
| CVE-2022-48351 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2022-48350 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48347 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48346 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2023 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48302 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48301 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled. | ||
| CVE-2022-48300 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48299 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48298 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. | ||
| CVE-2022-48297 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access. | ||
| CVE-2022-48295 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications). |
- risk 0.49cvss 7.5epss 0.00
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.01
The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The recovery mode for updates has a vulnerability that causes arbitrary disk modification. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the kernel.
- risk 0.49cvss 7.5epss 0.00
The facial recognition module has a vulnerability in input parameter verification. Successful exploitation of this vulnerability may cause failed facial recognition.
- risk 0.49cvss 7.5epss 0.00
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.
- risk 0.49cvss 7.5epss 0.00
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.
- risk 0.49cvss 7.5epss 0.00
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.00
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.00
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).
Page 20 of 54