Harmonyos
by Huawei
CVEs (1,079)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-58292 | Low | 0.21 | 3.3 | 0.00 | Oct 11, 2025 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58291 | Low | 0.21 | 3.3 | 0.00 | Oct 11, 2025 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58290 | Low | 0.21 | 3.3 | 0.00 | Oct 11, 2025 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58286 | Low | 0.21 | 3.3 | 0.00 | Oct 11, 2025 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-53176 | Low | 0.21 | 3.3 | 0.00 | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function. | ||
| CVE-2024-32989 | Low | 0.21 | 3.3 | 0.00 | May 14, 2024 | Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-41310 | Low | 0.21 | 3.3 | 0.00 | Sep 27, 2023 | Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background. | ||
| CVE-2023-31225 | Low | 0.21 | 3.3 | 0.00 | May 26, 2023 | The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability. | ||
| CVE-2021-22468 | Low | 0.21 | 3.3 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage. | ||
| CVE-2021-22464 | Low | 0.21 | 3.3 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause system Soft Restart. | ||
| CVE-2021-22457 | Low | 0.21 | 3.3 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause out-of-bounds write. | ||
| CVE-2021-22453 | Low | 0.21 | 3.3 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash. | ||
| CVE-2021-22294 | Low | 0.21 | 3.3 | 0.00 | Mar 2, 2021 | A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerability to issue commands repeatedly, exhausting system service resources. | ||
| CVE-2025-58282 | Low | 0.18 | 2.8 | 0.00 | Oct 11, 2025 | Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-57956 | Low | 0.18 | 2.8 | 0.00 | Feb 6, 2025 | Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-34849 | Low | 0.16 | 2.5 | 0.00 | Apr 13, 2026 | UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-42036 | Low | 0.16 | 2.5 | 0.00 | Aug 8, 2024 | Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-34851 | Low | 0.14 | 2.2 | 0.00 | Apr 13, 2026 | Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-34850 | Low | 0.12 | 1.9 | 0.00 | Apr 13, 2026 | Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability. |
- risk 0.21cvss 3.3epss 0.00
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- risk 0.21cvss 3.3epss 0.00
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- risk 0.21cvss 3.3epss 0.00
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- risk 0.21cvss 3.3epss 0.00
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- risk 0.21cvss 3.3epss 0.00
Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.
- risk 0.21cvss 3.3epss 0.00
Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.21cvss 3.3epss 0.00
Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background.
- risk 0.21cvss 3.3epss 0.00
The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability.
- risk 0.21cvss 3.3epss 0.00
A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address leakage.
- risk 0.21cvss 3.3epss 0.00
A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause system Soft Restart.
- risk 0.21cvss 3.3epss 0.00
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause out-of-bounds write.
- risk 0.21cvss 3.3epss 0.00
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
- risk 0.21cvss 3.3epss 0.00
A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerability to issue commands repeatedly, exhausting system service resources.
- risk 0.18cvss 2.8epss 0.00
Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.18cvss 2.8epss 0.00
Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.16cvss 2.5epss 0.00
UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.16cvss 2.5epss 0.00
Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.14cvss 2.2epss 0.00
Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.12cvss 1.9epss 0.00
Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.
Page 54 of 54