Harmonyos
by Huawei
CVEs (1,067)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44555 | 0.00 | — | 0.00 | Nov 9, 2022 | The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable. | |||
| CVE-2021-46852 | 0.00 | — | 0.00 | Nov 9, 2022 | The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-44563 | 0.00 | — | 0.00 | Nov 9, 2022 | There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-44561 | 0.00 | — | 0.00 | Nov 9, 2022 | The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction. | |||
| CVE-2022-44556 | 0.00 | — | 0.00 | Nov 8, 2022 | Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability. | |||
| CVE-2022-38977 | 0.00 | — | 0.00 | Oct 14, 2022 | The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data. | |||
| CVE-2022-41589 | 0.00 | — | 0.00 | Oct 14, 2022 | The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability. | |||
| CVE-2021-46839 | 0.00 | — | 0.00 | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access. | |||
| CVE-2022-38986 | 0.00 | — | 0.01 | Oct 14, 2022 | The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability. | |||
| CVE-2022-39011 | 0.00 | — | 0.00 | Oct 14, 2022 | The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module. | |||
| CVE-2022-41592 | 0.00 | — | 0.00 | Oct 14, 2022 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | |||
| CVE-2022-41600 | 0.00 | — | 0.00 | Oct 14, 2022 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | |||
| CVE-2022-41583 | 0.00 | — | 0.00 | Oct 14, 2022 | The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module. | |||
| CVE-2022-41595 | 0.00 | — | 0.00 | Oct 14, 2022 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | |||
| CVE-2022-38982 | 0.00 | — | 0.01 | Oct 14, 2022 | The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked. | |||
| CVE-2022-41586 | 0.00 | — | 0.00 | Oct 14, 2022 | The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-41593 | 0.00 | — | 0.00 | Oct 14, 2022 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | |||
| CVE-2022-41598 | 0.00 | — | 0.00 | Oct 14, 2022 | The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | |||
| CVE-2022-38985 | 0.00 | — | 0.00 | Oct 14, 2022 | The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality. | |||
| CVE-2022-38981 | 0.00 | — | 0.00 | Oct 14, 2022 | The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage. |
- CVE-2022-44555Nov 9, 2022risk 0.00cvss —epss 0.00
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
- CVE-2021-46852Nov 9, 2022risk 0.00cvss —epss 0.00
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-44563Nov 9, 2022risk 0.00cvss —epss 0.00
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-44561Nov 9, 2022risk 0.00cvss —epss 0.00
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.
- CVE-2022-44556Nov 8, 2022risk 0.00cvss —epss 0.00
Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability.
- CVE-2022-38977Oct 14, 2022risk 0.00cvss —epss 0.00
The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.
- CVE-2022-41589Oct 14, 2022risk 0.00cvss —epss 0.00
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affects system services and device availability.
- CVE-2021-46839Oct 14, 2022risk 0.00cvss —epss 0.00
The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.
- CVE-2022-38986Oct 14, 2022risk 0.00cvss —epss 0.01
The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.
- CVE-2022-39011Oct 14, 2022risk 0.00cvss —epss 0.00
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.
- CVE-2022-41592Oct 14, 2022risk 0.00cvss —epss 0.00
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41600Oct 14, 2022risk 0.00cvss —epss 0.00
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41583Oct 14, 2022risk 0.00cvss —epss 0.00
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.
- CVE-2022-41595Oct 14, 2022risk 0.00cvss —epss 0.00
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-38982Oct 14, 2022risk 0.00cvss —epss 0.01
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
- CVE-2022-41586Oct 14, 2022risk 0.00cvss —epss 0.00
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-41593Oct 14, 2022risk 0.00cvss —epss 0.00
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41598Oct 14, 2022risk 0.00cvss —epss 0.00
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-38985Oct 14, 2022risk 0.00cvss —epss 0.00
The facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-38981Oct 14, 2022risk 0.00cvss —epss 0.00
The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.
Page 38 of 54