Openharmony
by OpenHarmony
CVEs (178)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-27648 | Hig | 0.57 | 8.8 | 0.01 | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. | ||
| CVE-2025-0304 | Hig | 0.57 | 8.8 | 0.00 | Feb 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free. | ||
| CVE-2025-0303 | Hig | 0.57 | 8.8 | 0.00 | Feb 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow. | ||
| CVE-2024-47398 | Hig | 0.57 | 8.8 | 0.00 | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write. | ||
| CVE-2024-10074 | Hig | 0.57 | 8.8 | 0.00 | Dec 3, 2024 | in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free. | ||
| CVE-2024-41160 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free. | ||
| CVE-2024-41157 | Hig | 0.57 | 8.8 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free. | ||
| CVE-2022-38700 | Hig | 0.57 | 8.8 | 0.00 | Sep 9, 2022 | OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service. | ||
| CVE-2026-25781 | Hig | 0.55 | 8.4 | 0.00 | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered. | ||
| CVE-2025-27577 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | ||
| CVE-2025-27128 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | ||
| CVE-2025-25278 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | ||
| CVE-2025-24298 | Hig | 0.55 | 8.4 | 0.00 | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | ||
| CVE-2024-47797 | Hig | 0.55 | 8.4 | 0.00 | Nov 5, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write. | ||
| CVE-2024-47404 | Hig | 0.55 | 8.4 | 0.00 | Nov 5, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free. | ||
| CVE-2024-47137 | Hig | 0.55 | 8.4 | 0.00 | Nov 5, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write. | ||
| CVE-2024-39816 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | ||
| CVE-2024-38386 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | ||
| CVE-2023-43612 | Hig | 0.55 | 8.4 | 0.00 | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions. | ||
| CVE-2022-43451 | Hig | 0.55 | 8.4 | 0.00 | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to… |
- risk 0.57cvss 8.8epss 0.01
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
- risk 0.57cvss 8.8epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
- risk 0.57cvss 8.8epss 0.00
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
- risk 0.55cvss 8.4epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.
- risk 0.55cvss 8.4epss 0.00
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to…
Page 1 of 9