VYPR
Vendor

Openatom

Products
3
CVEs
104
Across products
104
Status
Private

Products

3

Recent CVEs

104
View all 104 CVEs →
  • CVE-2021-33643CriAug 10, 2022
    risk 0.59cvss 9.1epss 0.01

    An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

  • CVE-2025-0303HigFeb 7, 2025
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.

  • CVE-2024-41160HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2024-41157HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

  • CVE-2025-27577HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2025-27128HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

  • CVE-2025-25278HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

  • CVE-2025-24298HigAug 11, 2025
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

  • CVE-2024-47797HigNov 5, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

  • CVE-2024-47404HigNov 5, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

  • CVE-2024-39816HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2024-38386HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2023-43612HigNov 20, 2023
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.

  • CVE-2024-37077HigJul 2, 2024
    risk 0.53cvss 8.2epss 0.01

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2024-37030HigJul 2, 2024
    risk 0.53cvss 8.2epss 0.01

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

  • CVE-2024-36260HigJul 2, 2024
    risk 0.53cvss 8.2epss 0.01

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

  • CVE-2024-36243HigJul 2, 2024
    risk 0.53cvss 8.2epss 0.01

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

  • CVE-2024-28226HigApr 2, 2024
    risk 0.53cvss 8.1epss 0.01

    in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

  • CVE-2024-21860HigFeb 2, 2024
    risk 0.53cvss 8.2epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

  • CVE-2024-22092HigApr 2, 2024
    risk 0.50cvss 7.7epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.