VYPR

Vendor CVEs

Openatom

All CVEs

165 total · sorted by risk
  • CVE-2023-42774MedNov 20, 2023
    risk 0.40cvss 6.2epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.

  • CVE-2023-25947MedMar 10, 2023
    risk 0.40cvss 6.2epss 0.00

    The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious HAP package.

  • CVE-2021-33640MedDec 19, 2022
    risk 0.40cvss 6.2epss 0.01

    After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).

  • CVE-2022-38701MedSep 9, 2022
    risk 0.40cvss 6.2epss 0.00

    OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.

  • CVE-2023-6045MedNov 20, 2023
    risk 0.38cvss 5.9epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.

  • CVE-2025-52458MedMar 16, 2026
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-41432MedMar 16, 2026
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-27247MedJun 8, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

  • CVE-2025-26691MedJun 8, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

  • CVE-2025-24493MedJun 8, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.

  • CVE-2025-21098MedMar 4, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.

  • CVE-2025-20042MedMar 4, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.

  • CVE-2025-0302MedFeb 7, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.

  • CVE-2024-45070MedJan 7, 2025
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

  • CVE-2024-9978MedDec 3, 2024
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

  • CVE-2024-12082MedDec 3, 2024
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

  • CVE-2024-39806MedOct 8, 2024
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

  • CVE-2024-39612MedSep 2, 2024
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

  • CVE-2024-38382MedSep 2, 2024
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

  • CVE-2024-28951MedApr 2, 2024
    risk 0.36cvss 5.5epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

  • CVE-2023-24465MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.

  • CVE-2024-23808MedMay 7, 2024
    risk 0.34cvss 5.2epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.

  • CVE-2025-6969MedMar 16, 2026
    risk 0.33cvss 5.0epss 0.00

    in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.

  • CVE-2022-41686MedOct 14, 2022
    risk 0.33cvss 5.1epss 0.00

    OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound…

  • CVE-2024-21863MedFeb 2, 2024
    risk 0.31cvss 4.7epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

  • CVE-2024-0285MedFeb 2, 2024
    risk 0.31cvss 4.7epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

  • CVE-2024-54030MedJan 7, 2025
    risk 0.29cvss 4.4epss 0.00

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.

  • CVE-2024-39831MedOct 8, 2024
    risk 0.29cvss 4.4epss 0.00

    in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.

  • CVE-2024-21826MedMar 4, 2024
    risk 0.28cvss 4.3epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

  • CVE-2023-46708MedMar 4, 2024
    risk 0.28cvss 4.3epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

  • CVE-2023-45734MedFeb 2, 2024
    risk 0.27cvss 4.2epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

  • CVE-2024-21816MedMar 4, 2024
    risk 0.26cvss 4.0epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.

  • CVE-2023-49142MedJan 2, 2024
    risk 0.26cvss 4.0epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.

  • CVE-2023-49135MedJan 2, 2024
    risk 0.26cvss 4.0epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

  • CVE-2023-48360MedJan 2, 2024
    risk 0.26cvss 4.0epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

  • CVE-2023-47857MedJan 2, 2024
    risk 0.26cvss 4.0epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.

  • CVE-2023-47217MedNov 20, 2023
    risk 0.26cvss 4.0epss 0.00

    in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.

  • CVE-2023-0083MedMar 10, 2023
    risk 0.26cvss 4.0epss 0.00

    The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to…

  • CVE-2022-45126MedJan 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

  • CVE-2022-43662MedJan 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

  • CVE-2022-41802MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

  • CVE-2025-27132LowMay 6, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-24309LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-24301LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-23420LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-23414LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-23409LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-23240LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-22835LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2025-21084LowMar 4, 2025
    risk 0.25cvss 3.8epss 0.00

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios.