OpenHarmony records
18 published records for vendor openharmony.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication5
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-305 Authentication Bypass by Primary Weakness3
- CWE-20 Improper Input Validation1
- CWE-276 Incorrect Default Permissions1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-38700No exploit | multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.openharmony · openharmony · CWE-305 | High8.8 | — | 0.4% | Sep 9, 2022 |
35Monitor | CVE-2022-42463No exploit | Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed nopenharmony · openharmony · CWE-287 | High8.8 | — | 0.3% | Oct 14, 2022 |
31Monitor | CVE-2022-44455No exploit | The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.openharmony · openharmony · CWE-120 | High7.8 | — | 0.2% | Dec 8, 2022 |
31Monitor | CVE-2022-42464No exploit | Kernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device openharmony · openharmony · CWE-276 | High7.8 | — | 0.2% | Oct 14, 2022 |
31Monitor | CVE-2022-42488No exploit | Startup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user,openharmony · openharmony · CWE-287 | High7.8 | — | 0.2% | Oct 14, 2022 |
31Monitor | CVE-2022-43662No exploit | Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.openharmony · openharmony · CWE-120 | High7.8 | — | 0.2% | Jan 8, 2023 |
31Monitor | CVE-2022-45126No exploit | Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.openharmony · openharmony · CWE-120 | High7.8 | — | 0.2% | Jan 8, 2023 |
30Monitor | CVE-2022-43495No exploit | An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.openharmony · openharmony · CWE-476 | High7.5 | — | 0.7% | Nov 3, 2022 |
29Monitor | CVE-2022-36423No exploit | Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network deopenharmony · openharmony · CWE-16 | High7.4 | — | 0.3% | Sep 9, 2022 |
26Monitor | CVE-2022-43451No exploit | Multiple path traversal in appspawn and nwebspawn services.openharmony · openharmony · CWE-287 | Medium6.5 | — | 0.2% | Nov 3, 2022 |
22Monitor | CVE-2022-38081No exploit | Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weaopenharmony · openharmony · CWE-305 | Medium5.5 | — | 0.2% | Sep 9, 2022 |
22Monitor | CVE-2022-38064No exploit | windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.openharmony · openharmony · CWE-305 | Medium5.5 | — | 0.2% | Sep 9, 2022 |
22Monitor | CVE-2022-45118No exploit | Telephony in communication subsystem sends public events with personal data, but the permission is not set.openharmony · openharmony · CWE-287 | Medium5.5 | — | 0.2% | Dec 8, 2022 |
22Monitor | CVE-2022-43449No exploit | Arbitrary file read via download_server.openharmony · openharmony · CWE-20 | Medium5.5 | — | 0.2% | Nov 3, 2022 |
21Monitor | CVE-2022-45877No exploit | PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.openharmony · openharmony · CWE-287 | Medium5.3 | — | 0.2% | Dec 8, 2022 |
17Monitor | CVE-2022-41686No exploit | Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the openharmony · openharmony · CWE-787 | Medium4.4 | — | 0.3% | Oct 14, 2022 |
13Monitor | CVE-2022-38701No exploit | IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.openharmony · openharmony · CWE-122 | Low3.3 | — | 0.2% | Sep 9, 2022 |
13Monitor | CVE-2022-41802No exploit | Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.openharmony · openharmony · CWE-120 | Low3.3 | — | 0.2% | Dec 8, 2022 |
- CVE-2022-3870035Monitor
multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
HighCVSS 8.8No exploitEPSS 0%openharmony · openharmonySep 9, 2022
- CVE-2022-4246335Monitor
Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed n
HighCVSS 8.8No exploitEPSS 0%openharmony · openharmonyOct 14, 2022
- CVE-2022-4445531Monitor
The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.
HighCVSS 7.8No exploitEPSS 0%openharmony · openharmonyDec 8, 2022
- CVE-2022-4246431Monitor
Kernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device
HighCVSS 7.8No exploitEPSS 0%openharmony · openharmonyOct 14, 2022
- CVE-2022-4248831Monitor
Startup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user,
HighCVSS 7.8No exploitEPSS 0%openharmony · openharmonyOct 14, 2022
- CVE-2022-4366231Monitor
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.
HighCVSS 7.8No exploitEPSS 0%openharmony · openharmonyJan 8, 2023
- CVE-2022-4512631Monitor
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.
HighCVSS 7.8No exploitEPSS 0%openharmony · openharmonyJan 8, 2023
- CVE-2022-4349530Monitor
An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.
HighCVSS 7.5No exploitEPSS 1%openharmony · openharmonyNov 3, 2022
- CVE-2022-3642329Monitor
Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network de
HighCVSS 7.4No exploitEPSS 0%openharmony · openharmonySep 9, 2022
- CVE-2022-4345126Monitor
Multiple path traversal in appspawn and nwebspawn services.
MediumCVSS 6.5No exploitEPSS 0%openharmony · openharmonyNov 3, 2022
- CVE-2022-3808122Monitor
Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this wea
MediumCVSS 5.5No exploitEPSS 0%openharmony · openharmonySep 9, 2022
- CVE-2022-3806422Monitor
windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
MediumCVSS 5.5No exploitEPSS 0%openharmony · openharmonySep 9, 2022
- CVE-2022-4511822Monitor
Telephony in communication subsystem sends public events with personal data, but the permission is not set.
MediumCVSS 5.5No exploitEPSS 0%openharmony · openharmonyDec 8, 2022
- CVE-2022-4344922Monitor
Arbitrary file read via download_server.
MediumCVSS 5.5No exploitEPSS 0%openharmony · openharmonyNov 3, 2022
- CVE-2022-4587721Monitor
PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
MediumCVSS 5.3No exploitEPSS 0%openharmony · openharmonyDec 8, 2022
- CVE-2022-4168617Monitor
Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the
MediumCVSS 4.4No exploitEPSS 0%openharmony · openharmonyOct 14, 2022
- CVE-2022-3870113Monitor
IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
LowCVSS 3.3No exploitEPSS 0%openharmony · openharmonySep 9, 2022
- CVE-2022-4180213Monitor
Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.
LowCVSS 3.3No exploitEPSS 0%openharmony · openharmonyDec 8, 2022