OpenHarmony kayıtları
openharmony üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication5
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-305 Authentication Bypass by Primary Weakness3
- CWE-20 Improper Input Validation1
- CWE-276 Incorrect Default Permissions1
- CWE-476 NULL Pointer Dereference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2022-38700İstismar yok | multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.openharmony · openharmony · CWE-305 | Yüksek8,8 | — | %0,4 | 9 Eyl 2022 |
35İzleyin | CVE-2022-42463İstismar yok | Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed nopenharmony · openharmony · CWE-287 | Yüksek8,8 | — | %0,3 | 14 Eki 2022 |
31İzleyin | CVE-2022-44455İstismar yok | The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.openharmony · openharmony · CWE-120 | Yüksek7,8 | — | %0,2 | 8 Ara 2022 |
31İzleyin | CVE-2022-42464İstismar yok | Kernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device openharmony · openharmony · CWE-276 | Yüksek7,8 | — | %0,2 | 14 Eki 2022 |
31İzleyin | CVE-2022-42488İstismar yok | Startup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user,openharmony · openharmony · CWE-287 | Yüksek7,8 | — | %0,2 | 14 Eki 2022 |
31İzleyin | CVE-2022-43662İstismar yok | Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.openharmony · openharmony · CWE-120 | Yüksek7,8 | — | %0,2 | 8 Oca 2023 |
31İzleyin | CVE-2022-45126İstismar yok | Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.openharmony · openharmony · CWE-120 | Yüksek7,8 | — | %0,2 | 8 Oca 2023 |
30İzleyin | CVE-2022-43495İstismar yok | An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.openharmony · openharmony · CWE-476 | Yüksek7,5 | — | %0,7 | 3 Kas 2022 |
29İzleyin | CVE-2022-36423İstismar yok | Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network deopenharmony · openharmony · CWE-16 | Yüksek7,4 | — | %0,3 | 9 Eyl 2022 |
26İzleyin | CVE-2022-43451İstismar yok | Multiple path traversal in appspawn and nwebspawn services.openharmony · openharmony · CWE-287 | Orta6,5 | — | %0,2 | 3 Kas 2022 |
22İzleyin | CVE-2022-38081İstismar yok | Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weaopenharmony · openharmony · CWE-305 | Orta5,5 | — | %0,2 | 9 Eyl 2022 |
22İzleyin | CVE-2022-38064İstismar yok | windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.openharmony · openharmony · CWE-305 | Orta5,5 | — | %0,2 | 9 Eyl 2022 |
22İzleyin | CVE-2022-45118İstismar yok | Telephony in communication subsystem sends public events with personal data, but the permission is not set.openharmony · openharmony · CWE-287 | Orta5,5 | — | %0,2 | 8 Ara 2022 |
22İzleyin | CVE-2022-43449İstismar yok | Arbitrary file read via download_server.openharmony · openharmony · CWE-20 | Orta5,5 | — | %0,2 | 3 Kas 2022 |
21İzleyin | CVE-2022-45877İstismar yok | PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.openharmony · openharmony · CWE-287 | Orta5,3 | — | %0,2 | 8 Ara 2022 |
17İzleyin | CVE-2022-41686İstismar yok | Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the openharmony · openharmony · CWE-787 | Orta4,4 | — | %0,3 | 14 Eki 2022 |
13İzleyin | CVE-2022-38701İstismar yok | IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.openharmony · openharmony · CWE-122 | Düşük3,3 | — | %0,2 | 9 Eyl 2022 |
13İzleyin | CVE-2022-41802İstismar yok | Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.openharmony · openharmony · CWE-120 | Düşük3,3 | — | %0,2 | 8 Ara 2022 |
- CVE-2022-3870035İzleyin
multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
YüksekCVSS 8,8İstismar yokEPSS %0openharmony · openharmony9 Eyl 2022
- CVE-2022-4246335İzleyin
Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed n
YüksekCVSS 8,8İstismar yokEPSS %0openharmony · openharmony14 Eki 2022
- CVE-2022-4445531İzleyin
The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.
YüksekCVSS 7,8İstismar yokEPSS %0openharmony · openharmony8 Ara 2022
- CVE-2022-4246431İzleyin
Kernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device
YüksekCVSS 7,8İstismar yokEPSS %0openharmony · openharmony14 Eki 2022
- CVE-2022-4248831İzleyin
Startup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user,
YüksekCVSS 7,8İstismar yokEPSS %0openharmony · openharmony14 Eki 2022
- CVE-2022-4366231İzleyin
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.
YüksekCVSS 7,8İstismar yokEPSS %0openharmony · openharmony8 Oca 2023
- CVE-2022-4512631İzleyin
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.
YüksekCVSS 7,8İstismar yokEPSS %0openharmony · openharmony8 Oca 2023
- CVE-2022-4349530İzleyin
An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.
YüksekCVSS 7,5İstismar yokEPSS %1openharmony · openharmony3 Kas 2022
- CVE-2022-3642329İzleyin
Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network de
YüksekCVSS 7,4İstismar yokEPSS %0openharmony · openharmony9 Eyl 2022
- CVE-2022-4345126İzleyin
Multiple path traversal in appspawn and nwebspawn services.
OrtaCVSS 6,5İstismar yokEPSS %0openharmony · openharmony3 Kas 2022
- CVE-2022-3808122İzleyin
Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this wea
OrtaCVSS 5,5İstismar yokEPSS %0openharmony · openharmony9 Eyl 2022
- CVE-2022-3806422İzleyin
windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
OrtaCVSS 5,5İstismar yokEPSS %0openharmony · openharmony9 Eyl 2022
- CVE-2022-4511822İzleyin
Telephony in communication subsystem sends public events with personal data, but the permission is not set.
OrtaCVSS 5,5İstismar yokEPSS %0openharmony · openharmony8 Ara 2022
- CVE-2022-4344922İzleyin
Arbitrary file read via download_server.
OrtaCVSS 5,5İstismar yokEPSS %0openharmony · openharmony3 Kas 2022
- CVE-2022-4587721İzleyin
PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
OrtaCVSS 5,3İstismar yokEPSS %0openharmony · openharmony8 Ara 2022
- CVE-2022-4168617İzleyin
Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the
OrtaCVSS 4,4İstismar yokEPSS %0openharmony · openharmony14 Eki 2022
- CVE-2022-3870113İzleyin
IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
DüşükCVSS 3,3İstismar yokEPSS %0openharmony · openharmony9 Eyl 2022
- CVE-2022-4180213İzleyin
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.
DüşükCVSS 3,3İstismar yokEPSS %0openharmony · openharmony8 Ara 2022