Vendor CVEs
HarmonyOS
All CVEs
106 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34157 | Cri | 0.65 | 10.0 | 0.00 | Jun 16, 2023 | Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app. | ||
| CVE-2023-41294 | Cri | 0.64 | 9.8 | 0.00 | Sep 25, 2023 | The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. | ||
| CVE-2022-48479 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2022-48478 | Cri | 0.64 | 9.8 | 0.00 | May 26, 2023 | The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service. | ||
| CVE-2022-46316 | Cri | 0.64 | 9.8 | 0.00 | Dec 20, 2022 | A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | ||
| CVE-2022-38982 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked. | ||
| CVE-2022-38980 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions. | ||
| CVE-2021-40036 | Cri | 0.64 | 9.8 | 0.01 | Jun 13, 2022 | The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution. | ||
| CVE-2021-22480 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow. | ||
| CVE-2021-39996 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2022 | There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow. | ||
| CVE-2021-39990 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2022 | The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience. | ||
| CVE-2021-37128 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2022 | HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file. | ||
| CVE-2023-44107 | Cri | 0.59 | 9.1 | 0.00 | Oct 11, 2023 | Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity. | ||
| CVE-2023-39407 | Cri | 0.59 | 9.1 | 0.00 | Sep 25, 2023 | The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity. | ||
| CVE-2021-39982 | Cri | 0.59 | 9.1 | 0.01 | Jan 3, 2022 | Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications. | ||
| CVE-2021-37116 | Cri | 0.59 | 9.1 | 0.01 | Jan 3, 2022 | PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed. | ||
| CVE-2021-40002 | Hig | 0.57 | 8.8 | 0.00 | Jan 10, 2022 | The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end. | ||
| CVE-2021-40000 | Hig | 0.57 | 8.8 | 0.00 | Jan 10, 2022 | The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end. | ||
| CVE-2021-22376 | Hig | 0.55 | 8.4 | 0.00 | Jun 30, 2021 | A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions. | ||
| CVE-2021-37134 | Hig | 0.53 | 8.1 | 0.00 | Jan 3, 2022 | Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components. | ||
| CVE-2021-22470 | Hig | 0.51 | 7.8 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain. | ||
| CVE-2021-22458 | Hig | 0.51 | 7.8 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution. | ||
| CVE-2021-22451 | Hig | 0.51 | 7.8 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting. | ||
| CVE-2021-22425 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges. | ||
| CVE-2021-22423 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow. | ||
| CVE-2021-22422 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting. | ||
| CVE-2021-22421 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges. | ||
| CVE-2021-22420 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing.. | ||
| CVE-2021-22418 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting. | ||
| CVE-2021-22416 | Hig | 0.51 | 7.8 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution. | ||
| CVE-2023-52716 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2024 | Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52360 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2024 | Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2023-52110 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-44101 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2023 | The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-41305 | Hig | 0.49 | 7.5 | 0.00 | Sep 27, 2023 | Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-41303 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2023 | Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified. | ||
| CVE-2023-39409 | Hig | 0.49 | 7.5 | 0.00 | Sep 25, 2023 | DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | ||
| CVE-2022-48514 | Hig | 0.49 | 7.5 | 0.00 | Jul 6, 2023 | The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-46314 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | ||
| CVE-2022-46311 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-46310 | Hig | 0.49 | 7.5 | 0.00 | Dec 20, 2022 | The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-44554 | Hig | 0.49 | 7.5 | 0.00 | Nov 9, 2022 | The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device. | ||
| CVE-2022-38981 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage. | ||
| CVE-2022-38977 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data. | ||
| CVE-2022-37001 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash. | ||
| CVE-2021-40028 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2021-40025 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40022 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The weaver module has a vulnerability in parameter type verification,Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40021 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40018 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. |
- risk 0.65cvss 10.0epss 0.00
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.
- risk 0.64cvss 9.8epss 0.00
The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.
- risk 0.64cvss 9.8epss 0.00
A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.
- risk 0.64cvss 9.8epss 0.01
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
- risk 0.64cvss 9.8epss 0.01
The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.
- risk 0.64cvss 9.8epss 0.01
The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.
- risk 0.64cvss 9.8epss 0.01
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.
- risk 0.64cvss 9.8epss 0.01
There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.
- risk 0.64cvss 9.8epss 0.01
The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.
- risk 0.64cvss 9.8epss 0.01
HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.
- risk 0.59cvss 9.1epss 0.00
Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.
- risk 0.59cvss 9.1epss 0.00
The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.
- risk 0.59cvss 9.1epss 0.01
Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.
- risk 0.59cvss 9.1epss 0.01
PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.
- risk 0.57cvss 8.8epss 0.00
The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.
- risk 0.57cvss 8.8epss 0.00
The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.
- risk 0.55cvss 8.4epss 0.00
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.
- risk 0.53cvss 8.1epss 0.00
Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.
- risk 0.51cvss 7.8epss 0.00
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.
- risk 0.49cvss 7.5epss 0.00
The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.01
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.
- risk 0.49cvss 7.5epss 0.00
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
- risk 0.49cvss 7.5epss 0.00
The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- risk 0.49cvss 7.5epss 0.00
The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
- risk 0.49cvss 7.5epss 0.00
The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.
- risk 0.49cvss 7.5epss 0.00
The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.
- risk 0.49cvss 7.5epss 0.01
The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.
- risk 0.49cvss 7.5epss 0.01
The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.01
The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The weaver module has a vulnerability in parameter type verification,Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Page 1 of 3