CVE-2023-3116
- EPSS 0.02%
- Veröffentlicht 20.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:16:29
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.
CVE-2023-4753
- EPSS 0.02%
- Veröffentlicht 21.09.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:54
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input.
CVE-2023-22301
- EPSS 0.3%
- Veröffentlicht 10.03.2023 11:15:12
- Zuletzt bearbeitet 21.11.2024 07:44:29
The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerability which network attackers can launch a remote attack to obtain kernel memory data of the target system.
CVE-2023-22436
- EPSS 0.05%
- Veröffentlicht 10.03.2023 11:15:12
- Zuletzt bearbeitet 21.11.2024 07:44:48
The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.
CVE-2023-24465
- EPSS 0.05%
- Veröffentlicht 10.03.2023 11:15:12
- Zuletzt bearbeitet 21.11.2024 07:47:54
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to cra...
CVE-2023-25947
- EPSS 0.05%
- Veröffentlicht 10.03.2023 11:15:12
- Zuletzt bearbeitet 21.11.2024 07:50:29
The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious HAP package.
CVE-2023-0083
- EPSS 0.04%
- Veröffentlicht 10.03.2023 11:15:11
- Zuletzt bearbeitet 21.11.2024 07:36:31
The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing t...
CVE-2022-43662
- EPSS 0.06%
- Veröffentlicht 09.01.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:26:59
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
CVE-2022-45126
- EPSS 0.06%
- Veröffentlicht 09.01.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:28:48
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.
CVE-2023-0035
- EPSS 0.05%
- Veröffentlicht 09.01.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:36:26
softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privileg...