Vulnerabilities in OpenHarmony

177 results
Vexday analysis

Com 177 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o OpenHarmony apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de agentes maliciosos sobre suas vulnerabilidades. A ausência de CVEs de severidade crítica e de provas de conceito públicas reforça um perfil de risco contido no momento, embora 10 novas CVEs registradas nos últimos 90 dias indiquem atividade contínua de descoberta que merece acompanhamento. O tipo de falha mais frequente é CWE-416 (use-after-free), classe de vulnerabilidade que, por natureza, pode levar a execução de código arbitrário e elevação de privilégios, demandando atenção prioritária em revisões de código e processos de desenvolvimento. A CVE mais relevante no momento, CVE-2024-37185, apresenta EPSS de 0,0062, sinalizando baixa probabilidade de exploração iminente, mas ainda assim deve ser tratada como referência para priorização de mitigações.

CVE-2025-27132LOWarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2023-25947MEDIUMThe bundle management subsystem has a improper input validation when installing a HAP package.EPSS 0.2%CVE-2024-31078LOWBluetooth Service has a use after free vulnerabilityEPSS 0.2%CVE-2023-0083MEDIUMThe ArkUI framework subsystem doesn't check the input parameter,causing type confusion and invalid memory access.EPSS 0.2%CVE-2024-47398HIGHLiteos_a has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2025-52458MEDIUMarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2024-41160HIGHLiteos-A has an use after free vulnerabilityEPSS 0.2%CVE-2024-10074HIGHLiteos_a has an use after free vulnerabilityEPSS 0.2%CVE-2023-24465MEDIUMCommunication Wi-Fi  subsystem has a null pointer reference vulnerability when receving external data.EPSS 0.2%CVE-2023-4753LOWOpenHarmony v3.2.1 and prior version has a system call function usage errorEPSS 0.2%CVE-2024-29086LOWArkcompiler runtime has a stack overflow svulnerabilityEPSS 0.2%CVE-2026-0639LOWliteos_a has a missing release of memory vulnerabilityEPSS 0.2%CVE-2023-47857MEDIUMmultimedia camera has a UAF vulnerabilityEPSS 0.2%CVE-2023-49135MEDIUMmultimedia player has a UAF vulnerabilityEPSS 0.2%CVE-2024-21851LOWDsoftbus has an integer overflow vulnerabilityEPSS 0.2%CVE-2023-48360MEDIUMmultimedia player has a UAF vulnerabilityEPSS 0.2%CVE-2024-22180LOWCamera has a use after free vulnerabilityEPSS 0.2%CVE-2024-21834LOWArkui has a type confusion vulnerabilityEPSS 0.2%CVE-2025-20024LOWArkcompiler Ets Runtime has an integer overflow vulnerabilityEPSS 0.2%CVE-2025-20081LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%