Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-58043 | Hig | 0.47 | 7.3 | 0.00 | Mar 4, 2025 | Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-56451 | Hig | 0.47 | 7.3 | 0.00 | Jan 8, 2025 | Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-54097 | Hig | 0.47 | 7.3 | 0.00 | Dec 12, 2024 | Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity. | ||
| CVE-2024-36503 | Hig | 0.47 | 7.3 | 0.00 | Jun 14, 2024 | Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2026-28548 | Hig | 0.46 | 7.1 | 0.00 | Mar 5, 2026 | Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-66327 | Hig | 0.46 | 7.1 | 0.00 | Dec 8, 2025 | Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-48909 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2025 | Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54107 | Hig | 0.46 | 7.1 | 0.00 | Dec 12, 2024 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-54106 | Hig | 0.46 | 7.1 | 0.00 | Dec 12, 2024 | Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-51523 | Hig | 0.46 | 7.1 | 0.00 | Nov 5, 2024 | Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52719 | Hig | 0.46 | 7.1 | 0.00 | May 14, 2024 | Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2022-41577 | Hig | 0.46 | 7.1 | 0.00 | Oct 14, 2022 | The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability. | ||
| CVE-2021-22469 | Hig | 0.46 | 7.1 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read. | ||
| CVE-2021-22386 | Hig | 0.46 | 7.0 | 0.00 | Aug 10, 2021 | A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges. | ||
| CVE-2021-22326 | Hig | 0.46 | 7.1 | 0.00 | Jun 30, 2021 | A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability. | ||
| CVE-2026-28553 | Med | 0.45 | 6.9 | 0.00 | Apr 13, 2026 | Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-24922 | Med | 0.45 | 6.9 | 0.00 | Feb 6, 2026 | Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-53167 | Med | 0.45 | 6.9 | 0.00 | Jul 7, 2025 | Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-42033 | Med | 0.45 | 6.9 | 0.00 | Aug 8, 2024 | Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality. | ||
| CVE-2026-34864 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2026 | Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability. |
- risk 0.47cvss 7.3epss 0.00
Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.47cvss 7.3epss 0.00
Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.47cvss 7.3epss 0.00
Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.
- risk 0.47cvss 7.3epss 0.00
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.46cvss 7.1epss 0.00
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.46cvss 7.1epss 0.00
Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.46cvss 7.1epss 0.00
Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.46cvss 7.1epss 0.00
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.46cvss 7.1epss 0.00
Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.46cvss 7.1epss 0.00
Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.46cvss 7.1epss 0.00
Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.46cvss 7.1epss 0.00
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.
- risk 0.46cvss 7.1epss 0.00
A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.
- risk 0.46cvss 7.0epss 0.00
A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges.
- risk 0.46cvss 7.1epss 0.00
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.
- risk 0.45cvss 6.9epss 0.00
Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.45cvss 6.9epss 0.00
Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.45cvss 6.9epss 0.00
Authentication vulnerability in the distributed collaboration framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.45cvss 6.9epss 0.00
Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
- risk 0.44cvss 6.8epss 0.00
Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability.
Page 32 of 54