Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48613 | Med | 0.38 | 5.9 | 0.00 | Nov 8, 2023 | Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed. | ||
| CVE-2022-48509 | Med | 0.38 | 5.9 | 0.00 | Jul 6, 2023 | Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally. | ||
| CVE-2022-44563 | Med | 0.38 | 5.9 | 0.00 | Nov 9, 2022 | There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-39006 | Med | 0.38 | 5.9 | 0.00 | Sep 16, 2022 | The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2021-40055 | Med | 0.38 | 5.9 | 0.01 | Mar 10, 2022 | There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity. | ||
| CVE-2021-37085 | Med | 0.38 | 5.9 | 0.00 | Dec 7, 2021 | There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service. | ||
| CVE-2021-37082 | Med | 0.38 | 5.9 | 0.00 | Dec 7, 2021 | There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash. | ||
| CVE-2026-34855 | Med | 0.37 | 5.7 | 0.00 | Apr 13, 2026 | Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2026-34854 | Med | 0.37 | 5.7 | 0.00 | Apr 13, 2026 | UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2025-68967 | Med | 0.37 | 5.7 | 0.00 | Jan 14, 2026 | Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-68963 | Med | 0.37 | 5.7 | 0.00 | Jan 14, 2026 | Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54624 | Med | 0.37 | 5.7 | 0.00 | Aug 6, 2025 | Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-54618 | Med | 0.37 | 5.7 | 0.00 | Aug 6, 2025 | Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-53168 | Med | 0.37 | 5.7 | 0.00 | Jul 7, 2025 | Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness. | ||
| CVE-2024-57958 | Med | 0.37 | 5.7 | 0.00 | Feb 6, 2025 | Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2024-56437 | Med | 0.37 | 5.7 | 0.00 | Jan 8, 2025 | Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-54111 | Med | 0.37 | 5.7 | 0.00 | Dec 12, 2024 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-51521 | Med | 0.37 | 5.7 | 0.00 | Nov 5, 2024 | Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-34867 | Med | 0.36 | 5.6 | 0.00 | Apr 13, 2026 | Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-24927 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2026 | Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability. |
- risk 0.38cvss 5.9epss 0.00
Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.
- risk 0.38cvss 5.9epss 0.00
Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally.
- risk 0.38cvss 5.9epss 0.00
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.38cvss 5.9epss 0.00
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.38cvss 5.9epss 0.01
There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.
- risk 0.38cvss 5.9epss 0.00
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.
- risk 0.38cvss 5.9epss 0.00
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.
- risk 0.37cvss 5.7epss 0.00
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.37cvss 5.7epss 0.00
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.37cvss 5.7epss 0.00
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.37cvss 5.7epss 0.00
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.37cvss 5.7epss 0.00
Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.37cvss 5.7epss 0.00
Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.37cvss 5.7epss 0.00
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
- risk 0.37cvss 5.7epss 0.00
Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.37cvss 5.7epss 0.00
Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.37cvss 5.7epss 0.00
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.37cvss 5.7epss 0.00
Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.6epss 0.00
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability.
Page 41 of 54