Openharmony
Openharmony: vulnerabilidades y CVE
Openharmony tiene 28 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses10
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33565 | Baja (3.3) | 0.10% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
| CVE-2026-28751 | Baja (3.3) | 0.13% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
| CVE-2026-28733 | Media (6.5) | 0.15% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution. |
| CVE-2026-27781 | Baja (3.3) | 0.13% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
| CVE-2026-27766 | Media (5.5) | 0.11% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak. |
| CVE-2026-27648 | Alta (8.8) | 0.73% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. |
| CVE-2026-25850 | Media (5.5) | 0.13% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak |
| CVE-2026-25781 | Alta (8.4) | 0.15% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered. |
| CVE-2026-25110 | Baja (3.3) | 0.12% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
| CVE-2026-24792 | Alta (8.1) | 0.43% | — | 19 may 2026 | in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. |
| CVE-2022-45126 | Alta (7.8) | 0.18% | — | 9 ene 2023 | Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space… |
| CVE-2022-43662 | Alta (7.8) | 0.18% | — | 9 ene 2023 | Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space… |
| CVE-2022-45877 | Media (5.3) | 0.17% | — | 8 dic 2022 | OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks. |
| CVE-2022-45118 | Media (5.5) | 0.18% | — | 8 dic 2022 | OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and… |
| CVE-2022-44455 | Alta (7.8) | 0.22% | — | 8 dic 2022 | The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application… |
| CVE-2022-41802 | Baja (3.3) | 0.19% | — | 8 dic 2022 | Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space… |
| CVE-2022-43495 | Alta (7.5) | 0.66% | — | 3 nov 2022 | OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network. Network attakcers can send an abonormal packet when joining a network, cause a nullptr… |
| CVE-2022-43451 | Media (6.5) | 0.19% | — | 3 nov 2022 | OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other… |
| CVE-2022-43449 | Media (5.5) | 0.18% | — | 3 nov 2022 | OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can install an malicious application on the device and reveal any file from the filesystem that is… |
| CVE-2022-42488 | Alta (7.8) | 0.18% | — | 14 oct 2022 | OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root… |
| CVE-2022-42464 | Alta (7.8) | 0.19% | — | 14 oct 2022 | OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged… |
| CVE-2022-42463 | Alta (8.8) | 0.30% | — | 14 oct 2022 | OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by… |
| CVE-2022-41686 | Media (4.4) | 0.32% | — | 14 oct 2022 | OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The… |
| CVE-2022-38701 | Baja (3.3) | 0.20% | — | 9 sept 2022 | OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information. |
| CVE-2022-38700 | Alta (8.8) | 0.37% | — | 9 sept 2022 | OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service. |
| CVE-2022-38081 | Media (5.5) | 0.19% | — | 9 sept 2022 | OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to… |
| CVE-2022-38064 | Media (5.5) | 0.18% | — | 9 sept 2022 | OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information. |
| CVE-2022-36423 | Alta (7.4) | 0.33% | — | 9 sept 2022 | OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.