CVEs (156)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions. |
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input. |
The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when instal...Show more |
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause...Show more |
The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to roo...Show more |
The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerability which network attackers can launch a remote attack to obtain kernel memory data of the target syst...Show more |
The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to...Show more |
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack othe...Show more |
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attac...Show more |
2Openatom Openharmony2Openharmony OpenharmonyJun 17, 2026 Jan 9, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorr...Show more |
2Openatom Openharmony2Openharmony OpenharmonyJun 17, 2026 Jan 9, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorr...Show more |
2Openatom Openharmony2Openharmony OpenharmonyJun 17, 2026 Dec 8, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application wo...Show more |
2Openatom Openharmony2Openharmony OpenharmonyJun 17, 2026 Dec 8, 2022 N/A· v4 3.3 LOW· v3 N/A· v2 Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorre...Show more |
2Openatom Openharmony2Openharmony OpenharmonyJun 17, 2026 Oct 14, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unpriv...Show more |
2Openatom Openharmony2Openharmony OpenharmonyJun 17, 2026 Sep 9, 2022 N/A· v4 3.3 LOW· v3 N/A· v2 OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information. |
2Openatom Openharmony2Openharmony OpenharmonyJun 17, 2026 Sep 9, 2022 N/A· v4 7.4 HIGH· v3 N/A· v2 OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices. |