VYPR

Openharmony

by OpenHarmony

CVEs (178)

  • CVE-2026-27648HigMay 19, 2026
    risk 0.57cvss 8.8epss 0.01

    in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

  • CVE-2025-0304HigFeb 7, 2025
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2025-0303HigFeb 7, 2025
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.

  • CVE-2024-47398HigJan 7, 2025
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write.

  • CVE-2024-10074HigDec 3, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.

  • CVE-2024-41160HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2024-41157HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2022-38700HigSep 9, 2022
    risk 0.57cvss 8.8epss 0.00

    OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.

  • CVE-2026-25781HigMay 19, 2026
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

  • CVE-2025-27577HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2025-27128HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

  • CVE-2025-25278HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2025-24298HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

  • CVE-2024-47797HigNov 5, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

  • CVE-2024-47404HigNov 5, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

  • CVE-2024-47137HigNov 5, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

  • CVE-2024-39816HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2024-38386HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2023-43612HigNov 20, 2023
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.

  • CVE-2022-43451HigNov 3, 2022
    risk 0.55cvss 8.4epss 0.00

    OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to…

Page 1 of 9