Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54610 | Med | 0.35 | 5.4 | 0.00 | Aug 6, 2025 | Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-54609 | Med | 0.35 | 5.4 | 0.00 | Aug 6, 2025 | Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2021-40009 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2022 | There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2021-40003 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2022 | HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40001 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2022 | The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable. | ||
| CVE-2021-37013 | Med | 0.35 | 5.3 | 0.01 | Nov 23, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the availability of users is affected. | ||
| CVE-2025-66323 | Med | 0.34 | 5.3 | 0.00 | Dec 8, 2025 | Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-64313 | Med | 0.34 | 5.3 | 0.00 | Nov 28, 2025 | Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58285 | Med | 0.34 | 5.3 | 0.00 | Oct 11, 2025 | Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54628 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-54621 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures. | ||
| CVE-2025-54619 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability. | ||
| CVE-2025-53173 | Med | 0.34 | 5.3 | 0.00 | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function. | ||
| CVE-2024-58113 | Med | 0.34 | 5.3 | 0.00 | Apr 7, 2025 | Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-54096 | Med | 0.34 | 5.3 | 0.00 | Dec 12, 2024 | Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy. | ||
| CVE-2024-51518 | Med | 0.34 | 5.3 | 0.00 | Nov 5, 2024 | Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51514 | Med | 0.34 | 5.3 | 0.00 | Nov 5, 2024 | Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52551 | Med | 0.34 | 5.3 | 0.00 | Apr 8, 2024 | Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52717 | Med | 0.34 | 5.3 | 0.00 | Apr 7, 2024 | Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52368 | Med | 0.34 | 5.3 | 0.00 | Feb 18, 2024 | Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally. |
- risk 0.35cvss 5.4epss 0.00
Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.35cvss 5.4epss 0.00
Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.35cvss 5.3epss 0.01
There is an Out-of-bounds write vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
- risk 0.35cvss 5.3epss 0.01
HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.35cvss 5.3epss 0.01
The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable.
- risk 0.35cvss 5.3epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the availability of users is affected.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.
- risk 0.34cvss 5.3epss 0.00
Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.
- risk 0.34cvss 5.3epss 0.00
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of improper resource management in the memory management module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.34cvss 5.3epss 0.00
Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.34cvss 5.3epss 0.00
Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Page 45 of 54