Vendor CVEs
HarmonyOS
All CVEs
106 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40005 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The distributed data service component has a vulnerability in data access control. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40004 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-39989 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability may cause a process to restart. | ||
| CVE-2021-39988 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart. | ||
| CVE-2021-39987 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart. | ||
| CVE-2021-39985 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a Improper Validation of Array Index vulnerability.Successful exploitation of this vulnerability may cause a process to restart. | ||
| CVE-2021-39983 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart. | ||
| CVE-2021-39978 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy and security issues. | ||
| CVE-2021-39977 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart. | ||
| CVE-2021-39975 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Hilinksvc has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause denial of service attacks. | ||
| CVE-2021-39971 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality. | ||
| CVE-2021-39970 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission. | ||
| CVE-2021-39968 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Changlian Blocklist has a Business Logic Errors vulnerability .Successful exploitation of this vulnerability may expand the attack surface of the message class. | ||
| CVE-2021-39967 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-37126 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed. | ||
| CVE-2021-37098 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | Hilinksvc service exists a Data Processing Errors vulnerability .Successful exploitation of this vulnerability may cause application crash. | ||
| CVE-2023-52553 | Hig | 0.48 | 7.4 | 0.00 | Apr 8, 2024 | Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-41577 | Hig | 0.46 | 7.1 | 0.00 | Oct 14, 2022 | The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability. | ||
| CVE-2021-22469 | Hig | 0.46 | 7.1 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read. | ||
| CVE-2021-22326 | Hig | 0.46 | 7.1 | 0.00 | Jun 30, 2021 | A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability. | ||
| CVE-2022-34740 | Med | 0.42 | 6.5 | 0.00 | Jul 12, 2022 | The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation. | ||
| CVE-2022-41590 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2022 | Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability. | ||
| CVE-2021-22479 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2022 | The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash. | ||
| CVE-2021-22478 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2022 | The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage. | ||
| CVE-2021-22471 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash. | ||
| CVE-2021-22467 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address. | ||
| CVE-2021-22466 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash. | ||
| CVE-2021-22465 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable. | ||
| CVE-2021-22463 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure. | ||
| CVE-2021-22462 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash. | ||
| CVE-2021-22461 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash. | ||
| CVE-2021-22460 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism. | ||
| CVE-2021-22459 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable. | ||
| CVE-2021-22456 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable. | ||
| CVE-2021-22455 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released. | ||
| CVE-2021-22454 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump. | ||
| CVE-2021-22452 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address. | ||
| CVE-2021-22450 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion. | ||
| CVE-2021-22295 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2021 | A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler. | ||
| CVE-2021-22424 | Med | 0.36 | 5.5 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service. | ||
| CVE-2021-22419 | Med | 0.36 | 5.5 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos. | ||
| CVE-2021-22417 | Med | 0.36 | 5.5 | 0.00 | Aug 3, 2021 | A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage. | ||
| CVE-2021-22318 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2021 | A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service. | ||
| CVE-2021-22296 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2021 | A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system. | ||
| CVE-2021-40001 | Med | 0.35 | 5.3 | 0.01 | Jan 10, 2022 | The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable. | ||
| CVE-2022-46313 | Med | 0.34 | 5.3 | 0.00 | Dec 20, 2022 | The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone. | ||
| CVE-2021-39981 | Med | 0.34 | 5.3 | 0.00 | Jan 3, 2022 | Chang Lian application has a vulnerability which can be maliciously exploited to hide the calling number.Successful exploitation of this vulnerability allows you to make an anonymous call. | ||
| CVE-2021-39980 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could lead to sensitive information disclosure. | ||
| CVE-2021-37132 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission. | ||
| CVE-2021-37118 | Med | 0.34 | 5.3 | 0.01 | Jan 3, 2022 | The HwNearbyMain module has a Improper Handling of Exceptional Conditions vulnerability.Successful exploitation of this vulnerability may lead to message leak. |
- risk 0.49cvss 7.5epss 0.01
The distributed data service component has a vulnerability in data access control. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- risk 0.49cvss 7.5epss 0.01
The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- risk 0.49cvss 7.5epss 0.01
The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- risk 0.49cvss 7.5epss 0.01
The HwNearbyMain module has a Improper Validation of Array Index vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- risk 0.49cvss 7.5epss 0.01
The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- risk 0.49cvss 7.5epss 0.01
Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy and security issues.
- risk 0.49cvss 7.5epss 0.01
The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- risk 0.49cvss 7.5epss 0.01
Hilinksvc has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause denial of service attacks.
- risk 0.49cvss 7.5epss 0.01
Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
- risk 0.49cvss 7.5epss 0.01
HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission.
- risk 0.49cvss 7.5epss 0.01
Changlian Blocklist has a Business Logic Errors vulnerability .Successful exploitation of this vulnerability may expand the attack surface of the message class.
- risk 0.49cvss 7.5epss 0.01
There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed.
- risk 0.49cvss 7.5epss 0.01
Hilinksvc service exists a Data Processing Errors vulnerability .Successful exploitation of this vulnerability may cause application crash.
- risk 0.48cvss 7.4epss 0.00
Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.46cvss 7.1epss 0.00
The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.
- risk 0.46cvss 7.1epss 0.00
A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.
- risk 0.46cvss 7.1epss 0.00
A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.
- risk 0.42cvss 6.5epss 0.00
The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.
- risk 0.36cvss 5.5epss 0.00
Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation of this vulnerability affects the smartphone availability.
- risk 0.36cvss 5.5epss 0.00
The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.
- risk 0.36cvss 5.5epss 0.00
The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Use After Free vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Heap-based Buffer Overflow vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Use After Free vulnerability . Local attackers may exploit this vulnerability to cause Kernel Information disclosure.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause kernel crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Allocation of Resources Without Limits or Throttling vulnerability. Local attackers may exploit this vulnerability to cause nearby process crash.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a NULL Pointer Dereference vulnerability. Local attackers may exploit this vulnerability to cause System functions which are unavailable.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel System unavailable.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause the memory which is not released.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Improper Input Validation vulnerability. Local attackers may exploit this vulnerability to read at any address.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a Data Processing Errors vulnerability. Local attackers may exploit this vulnerability to cause Kernel Memory Leakage.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service.
- risk 0.36cvss 5.5epss 0.00
A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system.
- risk 0.35cvss 5.3epss 0.01
The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable.
- risk 0.34cvss 5.3epss 0.00
The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartphone's camera and microphone.
- risk 0.34cvss 5.3epss 0.00
Chang Lian application has a vulnerability which can be maliciously exploited to hide the calling number.Successful exploitation of this vulnerability allows you to make an anonymous call.
- risk 0.34cvss 5.3epss 0.01
Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could lead to sensitive information disclosure.
- risk 0.34cvss 5.3epss 0.01
PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.
- risk 0.34cvss 5.3epss 0.01
The HwNearbyMain module has a Improper Handling of Exceptional Conditions vulnerability.Successful exploitation of this vulnerability may lead to message leak.
Page 2 of 3