Openatom
Openatom Openharmony: vulnerabilities and CVEs
Openatom Openharmony has 156 published vulnerabilities, 7 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs156
Last 12 months7
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0639 | Medium (5.5) | 0.15% | — | Mar 16, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2025-6969 | Medium (5.5) | 0.15% | — | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-52458 | High (7.8) | 0.16% | — | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. |
| CVE-2025-41432 | High (7.8) | 0.17% | — | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. |
| CVE-2025-26474 | Low (3.3) | 0.14% | — | Mar 16, 2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios. |
| CVE-2025-25277 | High (7) | 0.15% | — | Mar 16, 2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios. |
| CVE-2025-12736 | Medium (6.5) | 0.17% | — | Mar 16, 2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource. |
| CVE-2025-27577 | High (7) | 0.10% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. |
| CVE-2025-27562 | Medium (5.5) | 0.12% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2025-27536 | Medium (5.5) | 0.12% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion. |
| CVE-2025-27128 | High (7.8) | 0.15% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. |
| CVE-2025-26690 | Medium (5.5) | 0.12% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |
| CVE-2025-25278 | High (7) | 0.11% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. |
| CVE-2025-25212 | Medium (5.5) | 0.12% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input. |
| CVE-2025-24925 | Medium (5.5) | 0.12% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2025-24844 | Medium (5.5) | 0.12% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2025-24298 | High (7.8) | 0.15% | — | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. |
| CVE-2025-27563 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-27247 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-27242 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-27131 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2025-26693 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-26691 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
| CVE-2025-25217 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |
| CVE-2025-24493 | Medium (4.7) | 0.10% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition. |
| CVE-2025-23235 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2025-21082 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2025-20063 | Medium (5.5) | 0.13% | — | Jun 8, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2025-27248 | Medium (5.5) | 0.14% | — | May 6, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |
| CVE-2025-27241 | Medium (5.5) | 0.14% | — | May 6, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |