Latest CVE Feed
-
8.4
HIGHCVE-2025-31175
Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.... Read more
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-31174
Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-31173
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-31172
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
6.8
MEDIUMCVE-2025-31171
File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-31170
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-20664
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-20663
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Information Disclosure
-
6.7
MEDIUMCVE-2025-20662
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2025-20661
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2025-20660
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-20659
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User intera... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Denial of Service
-
6.0
MEDIUMCVE-2025-20658
In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for explo... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-20657
In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AL... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Authorization
-
6.8
MEDIUMCVE-2025-20656
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not neede... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-20655
In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-20654
In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; I... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-58127
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2024-58126
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2024-58125
Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization