VYPR
Vendor

HarmonyOS

Products
39
CVEs
106
Across products
99
Status
Private

Products

39
View all 39 products →

Recent CVEs

106
View all 106 CVEs →
  • CVE-2023-34157CriJun 16, 2023
    risk 0.65cvss 10.0epss 0.00

    Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.

  • CVE-2023-41294CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.

  • CVE-2022-48479CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.

  • CVE-2022-48478CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.

  • CVE-2022-46316CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.00

    A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

  • CVE-2022-38982CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.

  • CVE-2022-38980CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.

  • CVE-2021-40036CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.

  • CVE-2021-22480CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.

  • CVE-2021-39996CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.

  • CVE-2021-39990CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.

  • CVE-2021-37128CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.

  • CVE-2023-44107CriOct 11, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.

  • CVE-2023-39407CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.

  • CVE-2021-39982CriJan 3, 2022
    risk 0.59cvss 9.1epss 0.01

    Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.

  • CVE-2021-37116CriJan 3, 2022
    risk 0.59cvss 9.1epss 0.01

    PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.

  • CVE-2021-40002HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-40000HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-22376HigJun 30, 2021
    risk 0.55cvss 8.4epss 0.00

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.

  • CVE-2021-37134HigJan 3, 2022
    risk 0.53cvss 8.1epss 0.00

    Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.