Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48294 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48289 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48288 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-48287 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-48286 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-47976 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections. | ||
| CVE-2022-47975 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2023 | The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46762 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-46761 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons. | ||
| CVE-2021-46868 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access. | ||
| CVE-2021-46867 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access. | ||
| CVE-2022-46328 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-46322 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions. | ||
| CVE-2022-46321 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-46317 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46315 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2022 | The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46314 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46312 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications. | ||
| CVE-2022-46311 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-46310 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality. |
- risk 0.49cvss 7.5epss 0.00
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.
- risk 0.49cvss 7.5epss 0.01
The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.
- risk 0.49cvss 7.5epss 0.00
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.00
The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.
- risk 0.49cvss 7.5epss 0.00
Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
- risk 0.49cvss 7.5epss 0.00
The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.01
The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.
- risk 0.49cvss 7.5epss 0.00
The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.
Page 21 of 54