İçeriğe atla
Noroxi

OpenHarmony kayıtları

openharmony üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2022-38700
    35İzleyin

    multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.

    YüksekCVSS 8,8İstismar yokEPSS %0

    openharmony · openharmony9 Eyl 2022

  • CVE-2022-42463
    35İzleyin

    Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed n

    YüksekCVSS 8,8İstismar yokEPSS %0

    openharmony · openharmony14 Eki 2022

  • CVE-2022-44455
    31İzleyin

    The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.

    YüksekCVSS 7,8İstismar yokEPSS %0

    openharmony · openharmony8 Ara 2022

  • CVE-2022-42464
    31İzleyin

    Kernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device

    YüksekCVSS 7,8İstismar yokEPSS %0

    openharmony · openharmony14 Eki 2022

  • CVE-2022-42488
    31İzleyin

    Startup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user,

    YüksekCVSS 7,8İstismar yokEPSS %0

    openharmony · openharmony14 Eki 2022

  • CVE-2022-43662
    31İzleyin

    Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.

    YüksekCVSS 7,8İstismar yokEPSS %0

    openharmony · openharmony8 Oca 2023

  • CVE-2022-45126
    31İzleyin

    Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.

    YüksekCVSS 7,8İstismar yokEPSS %0

    openharmony · openharmony8 Oca 2023

  • CVE-2022-43495
    30İzleyin

    An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.

    YüksekCVSS 7,5İstismar yokEPSS %1

    openharmony · openharmony3 Kas 2022

  • CVE-2022-36423
    29İzleyin

    Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network de

    YüksekCVSS 7,4İstismar yokEPSS %0

    openharmony · openharmony9 Eyl 2022

  • CVE-2022-43451
    26İzleyin

    Multiple path traversal in appspawn and nwebspawn services.

    OrtaCVSS 6,5İstismar yokEPSS %0

    openharmony · openharmony3 Kas 2022

  • CVE-2022-38081
    22İzleyin

    Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this wea

    OrtaCVSS 5,5İstismar yokEPSS %0

    openharmony · openharmony9 Eyl 2022

  • CVE-2022-38064
    22İzleyin

    windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.

    OrtaCVSS 5,5İstismar yokEPSS %0

    openharmony · openharmony9 Eyl 2022

  • CVE-2022-45118
    22İzleyin

    Telephony in communication subsystem sends public events with personal data, but the permission is not set.

    OrtaCVSS 5,5İstismar yokEPSS %0

    openharmony · openharmony8 Ara 2022

  • CVE-2022-43449
    22İzleyin

    Arbitrary file read via download_server.

    OrtaCVSS 5,5İstismar yokEPSS %0

    openharmony · openharmony3 Kas 2022

  • CVE-2022-45877
    21İzleyin

    PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.

    OrtaCVSS 5,3İstismar yokEPSS %0

    openharmony · openharmony8 Ara 2022

  • CVE-2022-41686
    17İzleyin

    Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the

    OrtaCVSS 4,4İstismar yokEPSS %0

    openharmony · openharmony14 Eki 2022

  • CVE-2022-38701
    13İzleyin

    IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.

    DüşükCVSS 3,3İstismar yokEPSS %0

    openharmony · openharmony9 Eyl 2022

  • CVE-2022-41802
    13İzleyin

    Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.

    DüşükCVSS 3,3İstismar yokEPSS %0

    openharmony · openharmony8 Ara 2022