Vendor CVEs
Openatom
All CVEs
165 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42774 | Med | 0.40 | 6.2 | 0.00 | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions. | ||
| CVE-2023-25947 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2023 | The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious HAP package. | ||
| CVE-2021-33640 | Med | 0.40 | 6.2 | 0.01 | Dec 19, 2022 | After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free). | ||
| CVE-2022-38701 | Med | 0.40 | 6.2 | 0.00 | Sep 9, 2022 | OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information. | ||
| CVE-2023-6045 | Med | 0.38 | 5.9 | 0.00 | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion. | ||
| CVE-2025-52458 | Med | 0.36 | 5.5 | 0.00 | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-41432 | Med | 0.36 | 5.5 | 0.00 | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-27247 | Med | 0.36 | 5.5 | 0.00 | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. | ||
| CVE-2025-26691 | Med | 0.36 | 5.5 | 0.00 | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. | ||
| CVE-2025-24493 | Med | 0.36 | 5.5 | 0.00 | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition. | ||
| CVE-2025-21098 | Med | 0.36 | 5.5 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check. | ||
| CVE-2025-20042 | Med | 0.36 | 5.5 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read. | ||
| CVE-2025-0302 | Med | 0.36 | 5.5 | 0.00 | Feb 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow. | ||
| CVE-2024-45070 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | ||
| CVE-2024-9978 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2024 | in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | ||
| CVE-2024-12082 | Med | 0.36 | 5.5 | 0.00 | Dec 3, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | ||
| CVE-2024-39806 | Med | 0.36 | 5.5 | 0.00 | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | ||
| CVE-2024-39612 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | ||
| CVE-2024-38382 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | ||
| CVE-2024-28951 | Med | 0.36 | 5.5 | 0.00 | Apr 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. | ||
| CVE-2023-24465 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash. | ||
| CVE-2024-23808 | Med | 0.34 | 5.2 | 0.00 | May 7, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference. | ||
| CVE-2025-6969 | Med | 0.33 | 5.0 | 0.00 | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. | ||
| CVE-2022-41686 | Med | 0.33 | 5.1 | 0.00 | Oct 14, 2022 | OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound… | ||
| CVE-2024-21863 | Med | 0.31 | 4.7 | 0.00 | Feb 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input. | ||
| CVE-2024-0285 | Med | 0.31 | 4.7 | 0.00 | Feb 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input. | ||
| CVE-2024-54030 | Med | 0.29 | 4.4 | 0.00 | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free. | ||
| CVE-2024-39831 | Med | 0.29 | 4.4 | 0.00 | Oct 8, 2024 | in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free. | ||
| CVE-2024-21826 | Med | 0.28 | 4.3 | 0.00 | Mar 4, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage. | ||
| CVE-2023-46708 | Med | 0.28 | 4.3 | 0.00 | Mar 4, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free. | ||
| CVE-2023-45734 | Med | 0.27 | 4.2 | 0.00 | Feb 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write. | ||
| CVE-2024-21816 | Med | 0.26 | 4.0 | 0.00 | Mar 4, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions. | ||
| CVE-2023-49142 | Med | 0.26 | 4.0 | 0.00 | Jan 2, 2024 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer. | ||
| CVE-2023-49135 | Med | 0.26 | 4.0 | 0.00 | Jan 2, 2024 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer. | ||
| CVE-2023-48360 | Med | 0.26 | 4.0 | 0.00 | Jan 2, 2024 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer. | ||
| CVE-2023-47857 | Med | 0.26 | 4.0 | 0.00 | Jan 2, 2024 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer. | ||
| CVE-2023-47217 | Med | 0.26 | 4.0 | 0.00 | Nov 20, 2023 | in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow. | ||
| CVE-2023-0083 | Med | 0.26 | 4.0 | 0.00 | Mar 10, 2023 | The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to… | ||
| CVE-2022-45126 | Med | 0.26 | 4.0 | 0.00 | Jan 9, 2023 | Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked. | ||
| CVE-2022-43662 | Med | 0.26 | 4.0 | 0.00 | Jan 9, 2023 | Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked. | ||
| CVE-2022-41802 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked. | ||
| CVE-2025-27132 | Low | 0.25 | 3.8 | 0.00 | May 6, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-24309 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-24301 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-23420 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-23414 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-23409 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-23240 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-22835 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | ||
| CVE-2025-21084 | Low | 0.25 | 3.8 | 0.00 | Mar 4, 2025 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios. |
- risk 0.40cvss 6.2epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.
- risk 0.40cvss 6.2epss 0.00
The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious HAP package.
- risk 0.40cvss 6.2epss 0.01
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
- risk 0.40cvss 6.2epss 0.00
OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
- risk 0.38cvss 5.9epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
- risk 0.36cvss 5.5epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.
- risk 0.36cvss 5.5epss 0.00
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.
- risk 0.34cvss 5.2epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.
- risk 0.33cvss 5.0epss 0.00
in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
- risk 0.33cvss 5.1epss 0.00
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound…
- risk 0.31cvss 4.7epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
- risk 0.31cvss 4.7epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
- risk 0.29cvss 4.4epss 0.00
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.
- risk 0.29cvss 4.4epss 0.00
in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.
- risk 0.28cvss 4.3epss 0.00
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.
- risk 0.28cvss 4.3epss 0.00
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.
- risk 0.27cvss 4.2epss 0.00
in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.
- risk 0.26cvss 4.0epss 0.00
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.
- risk 0.26cvss 4.0epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.
- risk 0.26cvss 4.0epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
- risk 0.26cvss 4.0epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
- risk 0.26cvss 4.0epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.
- risk 0.26cvss 4.0epss 0.00
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.
- risk 0.26cvss 4.0epss 0.00
The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to…
- risk 0.26cvss 4.0epss 0.00
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
- risk 0.26cvss 4.0epss 0.00
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
- risk 0.26cvss 4.0epss 0.00
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
- risk 0.25cvss 3.8epss 0.00
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios.
Page 2 of 4