Huawei Harmonyos
By the Year
In 2024 there have been 62 vulnerabilities in Huawei Harmonyos with an average score of 6.7 out of ten. Last year Harmonyos had 196 security vulnerabilities published. Right now, Harmonyos is on track to have less security vulnerabilities in 2024 than it did last year. Last year, the average CVE base score was greater by 0.82
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 62 | 6.72 |
2023 | 196 | 7.55 |
2022 | 257 | 7.54 |
2021 | 118 | 7.21 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Harmonyos vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Huawei Harmonyos Security Vulnerabilities
Input validation vulnerability in the USB service module
Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-47290
5.5 - Medium
- September 27, 2024
Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.
Permission vulnerability in the ActivityManagerService (AMS) module
Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-47291
5.5 - Medium
- September 27, 2024
Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.
Path traversal vulnerability in the Bluetooth module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-47292
5.5 - Medium
- September 27, 2024
Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Directory traversal
Out-of-bounds write vulnerability in the HAL-WIFI module
Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-47293
7.5 - High
- September 27, 2024
Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.
Memory Corruption
Access permission verification vulnerability in the input method framework module
Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-47294
7.5 - High
- September 27, 2024
Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.
Access permission verification vulnerability in the App Multiplier module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-9136
7.5 - High
- September 27, 2024
Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Access permission verification vulnerability in the camera driver module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-45446
5.5 - Medium
- September 04, 2024
Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.
Access control vulnerability in the camera framework module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-45447
5.5 - Medium
- September 04, 2024
Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Page table protection configuration vulnerability in the trusted firmware module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-45448
5.5 - Medium
- September 04, 2024
Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Access permission verification vulnerability in the ringtone setting module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-45449
5.5 - Medium
- September 04, 2024
Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Memory request vulnerability in the memory management module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-8298
5.5 - Medium
- September 04, 2024
Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Directory traversal vulnerability in the cust module
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2024-45443
9.1 - Critical
- September 04, 2024
Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
Directory traversal
Access permission verification vulnerability in the WMS module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-45444
5.5 - Medium
- September 04, 2024
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of resources not being closed or released in the keystore module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-45445
5.5 - Medium
- September 04, 2024
Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.
Insufficient Cleanup
Vulnerability of permission verification for APIs in the DownloadProviderMain module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-45442
7.5 - High
- September 04, 2024
Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.
Access control vulnerability in the SystemUI module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-42039
7.5 - High
- September 04, 2024
Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Input verification vulnerability in the system service module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-45441
7.5 - High
- September 04, 2024
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.
Permission control vulnerability in the software update module
CVE-2024-45450
7.5 - High
- September 04, 2024
Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Access control vulnerability in the security verification module
mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
CVE-2024-42033
7.1 - High
- August 08, 2024
Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.
Access permission verification vulnerability in the Notepad module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-42036
7.5 - High
- August 08, 2024
Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of uncaught exceptions in the Graphics module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-42037
6.2 - Medium
- August 08, 2024
Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
LaunchAnywhere vulnerability in the account module
CVE-2024-42034
5.5 - Medium
- August 08, 2024
LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission control vulnerability in the App Multiplier module
Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.
CVE-2024-42035
7.8 - High
- August 08, 2024
Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.
Access permission verification vulnerability in the content sharing pop-up module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-42030
6.2 - Medium
- August 08, 2024
Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Access permission verification vulnerability in the Settings module
CVE-2024-42031
7.5 - High
- August 08, 2024
Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Access permission verification vulnerability in the Contacts module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-42032
5.5 - Medium
- August 08, 2024
Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Permission verification vulnerability in the lock screen module
Impact: Successful exploitation of this vulnerability may affect availability
CVE-2023-7265
6.2 - Medium
- August 08, 2024
Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability
Privilege escalation vulnerability in the NMS module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2023-7271
5.5 - Medium
- July 25, 2024
Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.
Privilege escalation vulnerability in the account synchronisation module
CVE-2024-39670
5.5 - Medium
- July 25, 2024
Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.
Access control vulnerability in the security verification module
CVE-2024-39671
5.5 - Medium
- July 25, 2024
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Memory request logic vulnerability in the memory module
CVE-2024-39672
7.1 - High
- July 25, 2024
Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
Vulnerability of serialisation/deserialisation mismatch in the iAware module
CVE-2024-39673
7.1 - High
- July 25, 2024
Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Plaintext vulnerability in the Gallery search module
CVE-2024-39674
5.5 - Medium
- July 25, 2024
Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.
Vulnerability of unauthorized screenshot capturing in the WMS module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-36499
5.5 - Medium
- June 14, 2024
Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Privilege escalation vulnerability in the AMS module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-36500
5.5 - Medium
- June 14, 2024
Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Memory management vulnerability in the boottime module
Impact: Successful exploitation of this vulnerability
CVE-2024-36501
5.5 - Medium
- June 14, 2024
Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.
Out-of-bounds read vulnerability in the audio module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-36502
5.5 - Medium
- June 14, 2024
Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.
Out-of-bounds Read
Memory management vulnerability in the Gralloc module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-36503
5.5 - Medium
- June 14, 2024
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.
Use of Uninitialized Resource
Vulnerability of insufficient permission verification in the NearLink module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-5464
3.3 - Low
- June 14, 2024
Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Function vulnerabilities in the Calendar module
Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-5465
5.5 - Medium
- June 14, 2024
Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.
The Celia Keyboard module has a vulnerability in access control
CVE-2023-52100
7.5 - High
- January 16, 2024
The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.
Component exposure vulnerability in the Wi-Fi module
CVE-2023-52101
9.1 - Critical
- January 16, 2024
Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.
Vulnerability of parameters being not verified in the WMS module
CVE-2023-52102
7.5 - High
- January 16, 2024
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
Buffer overflow vulnerability in the FLP module
CVE-2023-52103
9.8 - Critical
- January 16, 2024
Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.
Classic Buffer Overflow
Vulnerability of parameters being not verified in the WMS module
CVE-2023-52104
7.5 - High
- January 16, 2024
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
The nearby module has a privilege escalation vulnerability
CVE-2023-52105
7.5 - High
- January 16, 2024
The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.
Improper Privilege Management
Vulnerability of permission verification for APIs in the DownloadProviderMain module
CVE-2023-52106
9.1 - Critical
- January 16, 2024
Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.
Vulnerability of foreground service restrictions being bypassed in the NMS module
CVE-2023-52099
7.5 - High
- January 16, 2024
Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.
Denial of Service (DoS) vulnerability in the DMS module
CVE-2023-52098
7.5 - High
- January 16, 2024
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.
Resource Exhaustion
Vulnerability of permissions being not strictly verified in the WMS module
CVE-2023-52107
7.5 - High
- January 16, 2024
Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
Incorrect Permission Assignment for Critical Resource
Vulnerability of process priorities being raised in the ActivityManagerService module
CVE-2023-52108
7.5 - High
- January 16, 2024
Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.
Data confidentiality vulnerability in the ScreenReader module
CVE-2023-52114
7.5 - High
- January 16, 2024
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.
The iaware module has a Use-After-Free (UAF) vulnerability
CVE-2023-52115
7.5 - High
- January 16, 2024
The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.
Dangling pointer
Permission management vulnerability in the multi-screen interaction module
CVE-2023-52116
7.5 - High
- January 16, 2024
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
Incorrect Permission Assignment for Critical Resource
The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.
CVE-2023-52110
7.5 - High
- January 16, 2024
The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.
Memory Corruption
Authorization vulnerability in the BootLoader module
CVE-2023-52111
7.5 - High
- January 16, 2024
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
AuthZ
Unauthorized file access vulnerability in the wallpaper service module
CVE-2023-52112
5.3 - Medium
- January 16, 2024
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.
Files or Directories Accessible to External Parties
launchAnyWhere vulnerability in the ActivityManagerService module
CVE-2023-52113
7.5 - High
- January 16, 2024
launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.
Out-of-bounds access vulnerability in the device authentication module
CVE-2023-44112
7.5 - High
- January 16, 2024
Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.
Out-of-bounds Read
Vulnerability of trust relationships being inaccurate in distributed scenarios
CVE-2023-44117
7.5 - High
- January 16, 2024
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of trust relationships being inaccurate in distributed scenarios
CVE-2023-4566
7.5 - High
- January 16, 2024
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of trust relationships being inaccurate in distributed scenarios
CVE-2023-52109
7.5 - High
- January 16, 2024
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of unauthorized access to email attachments in the email module
CVE-2023-49243
7.5 - High
- December 06, 2023
Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.
Permission verification vulnerability in distributed scenarios
CVE-2023-49247
7.5 - High
- December 06, 2023
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
Improper Certificate Validation
Permission management vulnerability in the module for disabling Sound Booster
CVE-2023-6273
5.3 - Medium
- December 06, 2023
Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.
Permission management vulnerability in the multi-user module
CVE-2023-49244
7.5 - High
- December 06, 2023
Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.
Unauthorized access vulnerability in the Huawei Share module
CVE-2023-49245
7.5 - High
- December 06, 2023
Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
Unauthorized access vulnerability in the card management module
CVE-2023-49246
7.5 - High
- December 06, 2023
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of unauthorized file access in the Settings app
CVE-2023-49248
5.5 - Medium
- December 06, 2023
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
API permission control vulnerability in the network management module
CVE-2023-49241
7.5 - High
- December 06, 2023
API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.
Free broadcast vulnerability in the running management module
CVE-2023-49242
7.5 - High
- December 06, 2023
Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of data verification errors in the kernel module
CVE-2023-44099
7.5 - High
- December 06, 2023
Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.
Improper Check for Unusual or Exceptional Conditions
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module
CVE-2023-44113
7.5 - High
- December 06, 2023
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
AuthZ
Permission management vulnerability in the PMS module
CVE-2023-46773
9.8 - Critical
- December 06, 2023
Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.
Incorrect Default Permissions
Unauthorized access vulnerability in the card management module
CVE-2023-49239
7.5 - High
- December 06, 2023
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
AuthZ
Unauthorized access vulnerability in the launcher module
CVE-2023-49240
7.5 - High
- December 06, 2023
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
AuthZ
Permission control vulnerability in the window management module
CVE-2023-46756
5.3 - Medium
- November 08, 2023
Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.
The remote PIN module has a vulnerability
CVE-2023-46757
7.5 - High
- November 08, 2023
The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality.
Permission management vulnerability in the multi-screen interaction module
CVE-2023-46758
7.5 - High
- November 08, 2023
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.
Permission control vulnerability in the call module
CVE-2023-46759
7.5 - High
- November 08, 2023
Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.
Out-of-bounds write vulnerability in the kernel driver module
CVE-2023-46762
7.5 - High
- November 08, 2023
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
Memory Corruption
Out-of-bounds write vulnerability in the kernel driver module
CVE-2023-46761
7.5 - High
- November 08, 2023
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
Memory Corruption
Vulnerability of background app permission management in the framework module
CVE-2023-46763
5.3 - Medium
- November 08, 2023
Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.
Unauthorized startup vulnerability of background apps
CVE-2023-46764
5.3 - Medium
- November 08, 2023
Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.
Vulnerability of uncaught exceptions in the NFC module
CVE-2023-46765
7.5 - High
- November 08, 2023
Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.
Out-of-bounds write vulnerability in the kernel driver module
CVE-2023-46760
7.5 - High
- November 08, 2023
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
Memory Corruption
Vulnerability of input parameters being not strictly verified in the input
CVE-2023-46755
5.3 - Medium
- November 08, 2023
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
Out-of-bounds write vulnerability in the kernel driver module
CVE-2023-46766
7.5 - High
- November 08, 2023
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
Memory Corruption
Out-of-bounds write vulnerability in the kernel driver module
CVE-2023-46767
7.5 - High
- November 08, 2023
Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.
Memory Corruption
Vulnerability of uncaught exceptions in the NFC module
CVE-2023-46774
7.5 - High
- November 08, 2023
Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.
Race condition vulnerability in the kernel module
CVE-2022-48613
5.9 - Medium
- November 08, 2023
Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.
Race Condition
Vulnerability of missing encryption in the card management module
CVE-2023-44098
7.5 - High
- November 08, 2023
Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
Missing Encryption of Sensitive Data
Security vulnerability in the face unlock module
CVE-2023-46771
7.5 - High
- November 08, 2023
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of improper permission control in the Booster module
CVE-2023-44115
7.5 - High
- November 08, 2023
Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Vulnerability of identity verification being bypassed in the face unlock module
CVE-2023-5801
9.1 - Critical
- November 08, 2023
Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.
Authentication Bypass by Spoofing
Use-After-Free (UAF) vulnerability in the dubai module
CVE-2023-46769
7.5 - High
- November 08, 2023
Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.
Dangling pointer
Out-of-bounds vulnerability in the sensor module
CVE-2023-46770
7.5 - High
- November 08, 2023
Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.
Memory Corruption
Multi-thread vulnerability in the idmap module
CVE-2023-46768
7.5 - High
- November 08, 2023
Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perform abnormally.
Dangling pointer
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
CVE-2023-44108
7.5 - High
- October 11, 2023
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
Object Type Confusion
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2023-44118
9.1 - Critical
- October 11, 2023
Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Huawei Emui or by Huawei? Click the Watch button to subscribe.