VYPR

Harmonyos

by Huawei

CVEs (1,079)

  • CVE-2024-42035HigAug 8, 2024
    risk 0.55cvss 8.4epss 0.00

    Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.

  • CVE-2024-39672HigJul 25, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

  • CVE-2024-32997HigMay 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2021-22376HigJun 30, 2021
    risk 0.55cvss 8.4epss 0.00

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.

  • CVE-2025-54622HigAug 6, 2025
    risk 0.54cvss 8.3epss 0.00

    Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54655HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module.

  • CVE-2025-48911HigJun 6, 2025
    risk 0.53cvss 8.2epss 0.00

    Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-48905HigJun 6, 2025
    risk 0.53cvss 8.1epss 0.00

    Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wasm exception types.

  • CVE-2024-51526HigNov 5, 2024
    risk 0.53cvss 8.2epss 0.00

    Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-34154HigJun 16, 2023
    risk 0.53cvss 8.2epss 0.00

    Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources.

  • CVE-2021-37134HigJan 3, 2022
    risk 0.53cvss 8.1epss 0.00

    Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.

  • CVE-2021-37074HigDec 8, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.

  • CVE-2025-68958HigJan 14, 2026
    risk 0.52cvss 8.0epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68956HigJan 14, 2026
    risk 0.52cvss 8.0epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68955HigJan 14, 2026
    risk 0.52cvss 8.0epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58310HigNov 28, 2025
    risk 0.52cvss 8.0epss 0.00

    Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54634HigAug 6, 2025
    risk 0.52cvss 8.0epss 0.00

    Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68968HigJan 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.

  • CVE-2025-58287HigOct 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-48903HigJun 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.

Page 9 of 54