Vulnerabilities > Openatom > Openharmony > 3.0.2

DATE CVE VULNERABILITY TITLE RISK
2024-04-02 CVE-2024-22098 Use After Free vulnerability in Openatom Openharmony
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.
local
low complexity
openatom CWE-416
8.8
2024-04-02 CVE-2024-22177 Improper Preservation of Permissions vulnerability in Openatom Openharmony
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.
local
low complexity
openatom CWE-281
5.5
2024-04-02 CVE-2024-29074 Unspecified vulnerability in Openatom Openharmony
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.
local
low complexity
openatom
8.8
2024-04-02 CVE-2024-29086 Allocation of Resources Without Limits or Throttling vulnerability in Openatom Openharmony
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.
local
low complexity
openatom CWE-770
5.5
2023-03-10 CVE-2023-0083 Type Confusion vulnerability in Openatom Openharmony
The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to crash.
local
low complexity
openatom CWE-843
5.5
2023-03-10 CVE-2023-24465 NULL Pointer Dereference vulnerability in Openatom Openharmony
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.
local
low complexity
openatom CWE-476
5.5
2023-01-09 CVE-2022-43662 Out-of-bounds Write vulnerability in multiple products
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.
local
low complexity
openharmony openatom CWE-787
7.8
2023-01-09 CVE-2022-45126 Out-of-bounds Write vulnerability in multiple products
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.
local
low complexity
openharmony openatom CWE-787
7.8
2023-01-09 CVE-2023-0035 Authentication Bypass by Capture-replay vulnerability in Openatom Openharmony
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.
local
low complexity
openatom CWE-294
7.8
2023-01-09 CVE-2023-0036 Authentication Bypass by Capture-replay vulnerability in Openatom Openharmony
platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.
local
low complexity
openatom CWE-294
7.8