Vulnerabilidades en OpenHarmony

177 resultados
Análisis Vexday

Com 177 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o OpenHarmony apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de agentes maliciosos sobre suas vulnerabilidades. A ausência de CVEs de severidade crítica e de provas de conceito públicas reforça um perfil de risco contido no momento, embora 10 novas CVEs registradas nos últimos 90 dias indiquem atividade contínua de descoberta que merece acompanhamento. O tipo de falha mais frequente é CWE-416 (use-after-free), classe de vulnerabilidade que, por natureza, pode levar a execução de código arbitrário e elevação de privilégios, demandando atenção prioritária em revisões de código e processos de desenvolvimento. A CVE mais relevante no momento, CVE-2024-37185, apresenta EPSS de 0,0062, sinalizando baixa probabilidade de exploração iminente, mas ainda assim deve ser tratada como referência para priorização de mitigações.

CVE-2022-38064MEDIUMwindowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.EPSS 0.2%CVE-2023-0035MEDIUMsoftbus_client_stub in communication subsystem has an authentication bypass vulnerability which allows an "SA relay attack".EPSS 0.2%CVE-2023-0036MEDIUMplatform_callback_stub in misc subsystem has an authentication bypass vulnerability which allows an "SA relay attack".EPSS 0.2%CVE-2024-29074MEDIUMTelephony has an improper input validation vulnerabilityEPSS 0.2%CVE-2024-24581MEDIUMArkcompiler runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2025-0587LOWArkcompiler Ets Runtime has an integer overflow vulnerabilityEPSS 0.2%CVE-2024-28951MEDIUMArkcompiler runtime has a use after free vulnerabilityEPSS 0.2%CVE-2025-22851MEDIUMLiteos_A has an integer overflow vulnerabilityEPSS 0.2%CVE-2022-43662MEDIUMKernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.EPSS 0.2%CVE-2022-45126MEDIUMKernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.EPSS 0.2%CVE-2024-21845LOWDsoftbus has an integer overflow vulnerabilityEPSS 0.2%CVE-2022-42488HIGHStartup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.EPSS 0.2%CVE-2024-54030MEDIUMCommunication_dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2023-22436HIGHThe kernel subsystem function check_permission_for_set_tokenid has an UAF vulnerability.EPSS 0.2%CVE-2022-45118MEDIUMTelephony in communication subsystem sends public events with personal data, but the permission is not set.EPSS 0.2%CVE-2024-21863MEDIUMDsoftbus has an improper input validation vulnerabilityEPSS 0.2%CVE-2022-43449MEDIUMArbitrary file read via download_server.EPSS 0.2%CVE-2022-45877HIGHPIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.EPSS 0.2%CVE-2024-39816HIGHArkcompiler Ets Runtime has an out-of-bounds write vulnerabilityEPSS 0.2%CVE-2025-0303HIGHLiteos_a has a buffer overflow vulnerabilityEPSS 0.2%