Vulnerability index

Browse CVEs

147 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openharmony MEDIUM 5.5
CVE-2024-39612

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Mitigation only
Fix from $1,600 2024-09-02
Openharmony CRITICAL 9.8
CVE-2024-37077

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-37185

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-36243

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-36260

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-37030

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony HIGH 7.8
CVE-2024-3759

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

Fix: 4.0.1+
Fix from $1,950 2024-05-07
Openharmony HIGH 7.8
CVE-2024-3758

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.

Fix: 4.0.1+
Fix from $1,950 2024-05-07
Openharmony MEDIUM 5.5
CVE-2024-3757

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.

Fix: 4.0.1+
Fix from $1,600 2024-05-07
Openharmony HIGH 7.8
CVE-2024-23808

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS th…

Fix: 4.0.1+
Fix from $1,950 2024-05-07
Openharmony HIGH 7.8
CVE-2024-27217

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

Fix: 4.0.1+
Fix from $1,950 2024-05-07
Openharmony MEDIUM 5.5
CVE-2024-31078

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference.

Fix: 4.0.1+
Fix from $1,600 2024-05-07
Openharmony HIGH 8.8
CVE-2024-29074

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.

Fix: after 3.2.4
Fix from $1,950 2024-04-02
Openharmony HIGH 7.8
CVE-2024-28951

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

Mitigation only
Fix from $1,950 2024-04-02
Openharmony MEDIUM 5.5
CVE-2024-29086

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.

Fix: after 3.2.4
Fix from $1,600 2024-04-02
Openharmony HIGH 7.5
CVE-2024-28226

in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

Fix: after 4.0
Fix from $1,950 2024-04-02
Openharmony HIGH 7.8
CVE-2024-24581

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.

Fix: after 4.0
Fix from $1,950 2024-04-02
Openharmony MEDIUM 5.5
CVE-2024-22177

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.

Fix: after 3.2.4
Fix from $1,600 2024-04-02
Openharmony MEDIUM 5.5
CVE-2024-22180

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

Fix: after 4.0
Fix from $1,600 2024-04-02
Openharmony HIGH 8.8
CVE-2024-22098

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

Fix: after 3.2.4
Fix from $1,950 2024-04-02
Openharmony HIGH 7.4
CVE-2024-22092

in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.

Fix: after 3.2.4
Fix from $1,950 2024-04-02
Openharmony MEDIUM 5.5
CVE-2024-21834

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

Fix: after 3.2.4
Fix from $1,600 2024-04-02
Openharmony MEDIUM 5.5
CVE-2024-21826

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

Fix: after 3.2.4
Fix from $1,600 2024-03-04
Openharmony MEDIUM 5.5
CVE-2024-21816

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.

Patch available
Fix from $1,600 2024-03-04
Openharmony HIGH 7.8
CVE-2023-46708

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

Fix: after 3.2.4
Fix from $1,950 2024-03-04
Openharmony MEDIUM 5.5
CVE-2023-49602

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

Fix: after 3.2.4
Fix from $1,600 2024-03-04
Openharmony MEDIUM 5.5
CVE-2023-25176

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Fix: after 3.2.4
Fix from $1,600 2024-03-04
Openharmony MEDIUM 6.2
CVE-2024-21863

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Fix: after 3.2.4
Fix from $1,600 2024-02-02
Openharmony HIGH 8.8
CVE-2024-21860

in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

Fix: after 3.2.4
Fix from $1,950 2024-02-02
Openharmony HIGH 7.8
CVE-2024-21851

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

Fix: after 3.2.4
Fix from $1,950 2024-02-02