VYPR

Vendor CVEs

HarmonyOS

All CVEs

106 total · sorted by risk
  • CVE-2023-34157CriJun 16, 2023
    risk 0.65cvss 10.0epss 0.00

    Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.

  • CVE-2023-41294CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.

  • CVE-2022-48479CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.

  • CVE-2022-48478CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.

  • CVE-2022-46316CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.00

    A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

  • CVE-2022-38982CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.

  • CVE-2022-38980CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.

  • CVE-2021-40036CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.

  • CVE-2021-22480CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.

  • CVE-2021-39996CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.

  • CVE-2021-39990CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.

  • CVE-2021-37128CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.

  • CVE-2023-44107CriOct 11, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.

  • CVE-2023-39407CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.

  • CVE-2021-39982CriJan 3, 2022
    risk 0.59cvss 9.1epss 0.01

    Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrary files by tampering with Phone Manager notifications.

  • CVE-2021-37116CriJan 3, 2022
    risk 0.59cvss 9.1epss 0.01

    PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.

  • CVE-2021-40002HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-40000HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-22376HigJun 30, 2021
    risk 0.55cvss 8.4epss 0.00

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.

  • CVE-2021-37134HigJan 3, 2022
    risk 0.53cvss 8.1epss 0.00

    Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.

  • CVE-2021-22470HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.

  • CVE-2021-22458HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.

  • CVE-2021-22451HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

  • CVE-2021-22425HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.

  • CVE-2021-22423HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow.

  • CVE-2021-22422HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

  • CVE-2021-22421HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Elevation of Privileges.

  • CVE-2021-22420HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..

  • CVE-2021-22418HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

  • CVE-2021-22416HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.

  • CVE-2023-52716HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52360HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2023-52110HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-44101HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-41305HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-41303HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.

  • CVE-2023-39409HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

  • CVE-2022-48514HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.00

    The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-46314HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-46311HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The contacts component has a free (undefined) provider vulnerability. Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2022-46310HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-44554HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.

  • CVE-2022-38981HigOct 14, 2022
    risk 0.49cvss 7.5epss 0.00

    The HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.

  • CVE-2022-38977HigOct 14, 2022
    risk 0.49cvss 7.5epss 0.00

    The HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resulting in modification of sensitive data.

  • CVE-2022-37001HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

  • CVE-2021-40028HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2021-40025HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40022HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The weaver module has a vulnerability in parameter type verification,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40021HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40018HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

Page 1 of 3