Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34158 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled. | ||
| CVE-2023-34156 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied. | ||
| CVE-2022-48495 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained. | ||
| CVE-2022-48491 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to display at any time. | ||
| CVE-2022-48488 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause unauthorized modifications to the desktop. | ||
| CVE-2023-34165 | Med | 0.34 | 5.3 | 0.00 | Jun 16, 2023 | Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions. | ||
| CVE-2023-0117 | Med | 0.34 | 5.3 | 0.00 | May 26, 2023 | The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime. | ||
| CVE-2022-48361 | Med | 0.34 | 5.3 | 0.00 | Mar 27, 2023 | The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in reading AOD theme resources. | ||
| CVE-2022-48296 | Med | 0.34 | 5.3 | 0.00 | Feb 9, 2023 | The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices. | ||
| CVE-2022-46318 | Med | 0.34 | 5.3 | 0.00 | Dec 20, 2022 | The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings. | ||
| CVE-2022-46313 | Med | 0.34 | 5.3 | 0.00 | Dec 20, 2022 | The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone. | ||
| CVE-2022-44560 | Med | 0.34 | 5.3 | 0.00 | Nov 9, 2022 | The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified. | ||
| CVE-2022-44553 | Med | 0.34 | 5.3 | 0.00 | Nov 9, 2022 | The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically. | ||
| CVE-2021-46811 | Med | 0.34 | 5.3 | 0.00 | Jun 13, 2022 | HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information. | ||
| CVE-2021-46785 | Med | 0.34 | 5.3 | 0.01 | May 13, 2022 | The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier. | ||
| CVE-2021-39981 | Med | 0.34 | 5.3 | 0.00 | Jan 3, 2022 | Chang Lian application has a vulnerability which can be maliciously exploited to hide the calling number.Successful exploitation of this vulnerability allows you to make an anonymous call. | ||
| CVE-2021-39980 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could lead to sensitive information disclosure. | ||
| CVE-2021-37132 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission. | ||
| CVE-2021-37118 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a Improper Handling of Exceptional Conditions vulnerability.Successful exploitation of this vulnerability may lead to message leak. | ||
| CVE-2021-37114 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | There is an Out-of-bounds read vulnerability in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. |
- risk 0.34cvss 5.3epss 0.00
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnerability may cause services to be denied.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead to ads and other windows to display at any time.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause unauthorized modifications to the desktop.
- risk 0.34cvss 5.3epss 0.00
Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.
- risk 0.34cvss 5.3epss 0.00
The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime.
- risk 0.34cvss 5.3epss 0.00
The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a failure in reading AOD theme resources.
- risk 0.34cvss 5.3epss 0.00
The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasts from malicious apps, conveying false alarm information about external storage devices.
- risk 0.34cvss 5.3epss 0.00
The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings.
- risk 0.34cvss 5.3epss 0.00
The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.
- risk 0.34cvss 5.3epss 0.00
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.
- risk 0.34cvss 5.3epss 0.00
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
- risk 0.34cvss 5.3epss 0.00
HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.
- risk 0.34cvss 5.3epss 0.01
The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.
- risk 0.34cvss 5.3epss 0.00
Chang Lian application has a vulnerability which can be maliciously exploited to hide the calling number.Successful exploitation of this vulnerability allows you to make an anonymous call.
- risk 0.34cvss 5.3epss 0.01
Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could lead to sensitive information disclosure.
- risk 0.34cvss 5.3epss 0.01
PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.
- risk 0.34cvss 5.3epss 0.01
The HwNearbyMain module has a Improper Handling of Exceptional Conditions vulnerability.Successful exploitation of this vulnerability may lead to message leak.
- risk 0.34cvss 5.3epss 0.01
There is an Out-of-bounds read vulnerability in Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
Page 47 of 54