HarmonyOS
Products
39- 52 CVEs
- 7 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- View all 39 products →
Recent CVEs
106| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34157 | Cri | 0.65 | 10.0 | 0.00 | Jun 16, 2023 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | ||
| CVE-2023-41294 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. | ||
| CVE-2022-48479 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2022-48478 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2022-46316 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | ||
| CVE-2022-38982 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked. | ||
| CVE-2022-38980 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions. | ||
| CVE-2021-40036 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2022 | The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution. | ||
| CVE-2021-22480 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow. | ||
| CVE-2021-39996 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2022 | There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow. | ||
| CVE-2021-39990 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2022 | The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience. | ||
| CVE-2021-37128 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2022 | HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file. | ||
| CVE-2023-44107 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-39407 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2021-39982 | Cri | 0.59 | 9.1 | 0.01 | Jan 3, 2022 | Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications. | ||
| CVE-2021-37116 | Cri | 0.59 | 9.1 | 0.01 | Jan 3, 2022 | PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed. | ||
| CVE-2021-40002 | Hig | 0.57 | 8.8 | 0.00 | Jan 10, 2022 | The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end. | ||
| CVE-2021-40000 | Hig | 0.57 | 8.8 | 0.00 | Jan 10, 2022 | The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end. | ||
| CVE-2021-22376 | Hig | 0.55 | 8.4 | 0.00 | Jun 30, 2021 | A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions. | ||
| CVE-2021-37134 | Hig | 0.53 | 8.1 | 0.00 | Jan 3, 2022 | Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components. |
- risk 0.65cvss 10.0epss 0.00
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
- risk 0.64cvss 9.8epss 0.00
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- risk 0.64cvss 9.8epss 0.01
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
- risk 0.64cvss 9.8epss 0.01
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
- risk 0.64cvss 9.8epss 0.01
The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.
- risk 0.64cvss 9.8epss 0.01
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.
- risk 0.64cvss 9.8epss 0.01
There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.
- risk 0.64cvss 9.8epss 0.01
The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.
- risk 0.64cvss 9.8epss 0.01
HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.59cvss 9.1epss 0.01
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.
- risk 0.59cvss 9.1epss 0.01
PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.
- risk 0.57cvss 8.8epss 0.00
The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.
- risk 0.57cvss 8.8epss 0.00
The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.
- risk 0.55cvss 8.4epss 0.00
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.
- risk 0.53cvss 8.1epss 0.00
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.