Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39671 | Cri | 0.60 | 9.3 | 0.00 | Jul 25, 2024 | Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-34865 | Cri | 0.59 | 9.1 | 0.00 | Apr 13, 2026 | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2023-52538 | Cri | 0.59 | 9.1 | 0.00 | Apr 8, 2024 | Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-30415 | Cri | 0.59 | 9.1 | 0.00 | Apr 7, 2024 | Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52369 | Cri | 0.59 | 9.1 | 0.00 | Feb 18, 2024 | Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-52101 | Cri | 0.59 | 9.1 | 0.00 | Jan 16, 2024 | Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-5801 | Cri | 0.59 | 9.1 | 0.00 | Nov 8, 2023 | Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality. | ||
| CVE-2023-44118 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2023-44107 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-41296 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality. | ||
| CVE-2023-39407 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2023-39403 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39402 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39401 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39400 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39399 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39398 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. | ||
| CVE-2023-39385 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access. | ||
| CVE-2021-46895 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2023 | Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop. | ||
| CVE-2023-37245 | Cri | 0.59 | 9.1 | 0.00 | Jul 6, 2023 | Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem. |
- risk 0.60cvss 9.3epss 0.00
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.59cvss 9.1epss 0.00
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.59cvss 9.1epss 0.00
Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
- risk 0.59cvss 9.1epss 0.00
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.
- risk 0.59cvss 9.1epss 0.00
Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.
Page 5 of 54