Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38983 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution. | ||
| CVE-2022-38982 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked. | ||
| CVE-2022-38980 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions. | ||
| CVE-2022-39009 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions. | ||
| CVE-2022-39007 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation. | ||
| CVE-2022-39002 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice. | ||
| CVE-2022-39000 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup. | ||
| CVE-2022-38999 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | ||
| CVE-2021-40017 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access. | ||
| CVE-2022-37003 | Cri | 0.64 | 9.8 | 0.00 | Aug 10, 2022 | The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files. | ||
| CVE-2022-37002 | Cri | 0.64 | 9.8 | 0.00 | Aug 10, 2022 | The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background. | ||
| CVE-2021-40036 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2022 | The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution. | ||
| CVE-2022-29794 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality. | ||
| CVE-2021-46786 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access. | ||
| CVE-2022-22258 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2022 | The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege. | ||
| CVE-2021-40050 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow. | ||
| CVE-2021-22480 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow. | ||
| CVE-2021-22434 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22433 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22432 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access. |
- risk 0.64cvss 9.8epss 0.01
The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
- risk 0.64cvss 9.8epss 0.01
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
- risk 0.64cvss 9.8epss 0.01
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.
- risk 0.64cvss 9.8epss 0.01
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.
- risk 0.64cvss 9.8epss 0.01
Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.
- risk 0.64cvss 9.8epss 0.01
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.
- risk 0.64cvss 9.8epss 0.01
The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- risk 0.64cvss 9.8epss 0.01
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.
- risk 0.64cvss 9.8epss 0.00
The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.
- risk 0.64cvss 9.8epss 0.00
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.
- risk 0.64cvss 9.8epss 0.01
The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.
- risk 0.64cvss 9.8epss 0.01
The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.
- risk 0.64cvss 9.8epss 0.01
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- risk 0.64cvss 9.8epss 0.01
The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.
- risk 0.64cvss 9.8epss 0.01
There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.
- risk 0.64cvss 9.8epss 0.01
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
Page 3 of 54