Skip to content
Noroxi

OpenHarmony records

18 published records for vendor openharmony.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

18 records
  • multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.

    HighCVSS 8.8No exploitEPSS 0%

    openharmony · openharmonySep 9, 2022

  • Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed n

    HighCVSS 8.8No exploitEPSS 0%

    openharmony · openharmonyOct 14, 2022

  • The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.

    HighCVSS 7.8No exploitEPSS 0%

    openharmony · openharmonyDec 8, 2022

  • Kernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device

    HighCVSS 7.8No exploitEPSS 0%

    openharmony · openharmonyOct 14, 2022

  • Startup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user,

    HighCVSS 7.8No exploitEPSS 0%

    openharmony · openharmonyOct 14, 2022

  • Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.

    HighCVSS 7.8No exploitEPSS 0%

    openharmony · openharmonyJan 8, 2023

  • Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.

    HighCVSS 7.8No exploitEPSS 0%

    openharmony · openharmonyJan 8, 2023

  • An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.

    HighCVSS 7.5No exploitEPSS 1%

    openharmony · openharmonyNov 3, 2022

  • Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network de

    HighCVSS 7.4No exploitEPSS 0%

    openharmony · openharmonySep 9, 2022

  • Multiple path traversal in appspawn and nwebspawn services.

    MediumCVSS 6.5No exploitEPSS 0%

    openharmony · openharmonyNov 3, 2022

  • Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this wea

    MediumCVSS 5.5No exploitEPSS 0%

    openharmony · openharmonySep 9, 2022

  • windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.

    MediumCVSS 5.5No exploitEPSS 0%

    openharmony · openharmonySep 9, 2022

  • Telephony in communication subsystem sends public events with personal data, but the permission is not set.

    MediumCVSS 5.5No exploitEPSS 0%

    openharmony · openharmonyDec 8, 2022

  • Arbitrary file read via download_server.

    MediumCVSS 5.5No exploitEPSS 0%

    openharmony · openharmonyNov 3, 2022

  • PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.

    MediumCVSS 5.3No exploitEPSS 0%

    openharmony · openharmonyDec 8, 2022

  • Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the

    MediumCVSS 4.4No exploitEPSS 0%

    openharmony · openharmonyOct 14, 2022

  • IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.

    LowCVSS 3.3No exploitEPSS 0%

    openharmony · openharmonySep 9, 2022

  • Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.

    LowCVSS 3.3No exploitEPSS 0%

    openharmony · openharmonyDec 8, 2022