Vulnerabilities > Huawei > Harmonyos > High

DATE CVE VULNERABILITY TITLE RISK
2022-09-16 CVE-2022-39001 Path Traversal vulnerability in Huawei Emui, Harmonyos and Magic UI
The number identification module has a path traversal vulnerability.
network
low complexity
huawei CWE-22
7.5
2022-09-16 CVE-2022-39004 Memory Leak vulnerability in Huawei Emui, Harmonyos and Magic UI
The MPTCP module has the memory leak vulnerability.
network
low complexity
huawei CWE-401
7.5
2022-09-16 CVE-2022-39005 Memory Leak vulnerability in Huawei Emui, Harmonyos and Magic UI
The MPTCP module has the memory leak vulnerability.
network
low complexity
huawei CWE-401
7.5
2022-09-16 CVE-2022-39010 Unspecified vulnerability in Huawei Emui and Harmonyos
The HwChrService module has a vulnerability in permission control.
network
low complexity
huawei
7.5
2022-08-10 CVE-2022-37001 Unspecified vulnerability in Huawei Harmonyos 2.0
The diag-router module has a vulnerability in intercepting excessive long and short instructions.
network
low complexity
huawei
7.5
2022-08-10 CVE-2022-37004 Unspecified vulnerability in Huawei Emui, Harmonyos and Magic UI
The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE).
network
low complexity
huawei
7.5
2022-08-10 CVE-2022-37005 Argument Injection or Modification vulnerability in Huawei Emui, Harmonyos and Magic UI
The Settings application has an argument injection vulnerability.
network
low complexity
huawei CWE-88
7.5
2022-08-10 CVE-2022-37006 Incorrect Default Permissions vulnerability in Huawei Emui and Harmonyos
Permission control vulnerability in the network module.
network
low complexity
huawei CWE-276
7.5
2022-08-10 CVE-2022-37007 Out-of-bounds Read vulnerability in Huawei Emui, Harmonyos and Magic UI
The chinadrm module has an out-of-bounds read vulnerability.
network
low complexity
huawei CWE-125
7.5
2022-08-10 CVE-2022-37008 Insufficient Verification of Data Authenticity vulnerability in Huawei Emui, Harmonyos and Magic UI
The recovery module has a vulnerability of bypassing the verification of an update package before use.
network
low complexity
huawei CWE-345
7.5