Latest CVE Feed
-
6.7
MEDIUMCVE-2024-45781
A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issues and eventually ... Read more
- Published: Feb. 18, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2024-45776
When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads and writes. This fl... Read more
- Published: Feb. 18, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-8463
Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Parameter Injection.This issue affects SecHard: before 3.6.2-20250805.... Read more
Affected Products :- Published: Sep. 17, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-46593
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Denial of Service
-
6.2
MEDIUMCVE-2025-46591
Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-46589
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
7.7
HIGHCVE-2025-46588
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-46586
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-31174
Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2025-31171
File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-27521
Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Mar. 04, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-9136
Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Sep. 27, 2024
- Modified: Sep. 18, 2025
-
6.2
MEDIUMCVE-2024-58050
Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Mar. 04, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
6.2
MEDIUMCVE-2024-58046
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Mar. 04, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-57955
Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-57954
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-56439
Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-56438
Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Jan. 08, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-56436
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-56435
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Information Disclosure