Loading HuntDB...

Vulnerabilities

CVE-2024-54030

MEDIUM

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through use after free.

Published Jan 07, 2025

CVE-2024-47398

HIGH

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write.

Published Jan 07, 2025

CVE-2024-45070

MEDIUM

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Published Jan 07, 2025

CVE-2024-9978

MEDIUM

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Published Dec 03, 2024

CVE-2024-12082

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Published Dec 03, 2024

CVE-2024-10074

HIGH

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.

Published Dec 03, 2024

CVE-2024-47402

LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Published Nov 05, 2024

CVE-2024-47137

HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Published Nov 05, 2024

CVE-2024-47404

HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

Published Nov 05, 2024

CVE-2024-47797

HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Published Nov 05, 2024

CVE-2024-45382

LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

Published Oct 08, 2024

CVE-2024-43697

LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.

Published Oct 08, 2024

CVE-2024-43696

LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

Published Oct 08, 2024

CVE-2024-39831

MEDIUM

in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.

Published Oct 08, 2024

CVE-2024-39806

MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Published Oct 08, 2024

CVE-2024-41160

HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

Published Sep 02, 2024

CVE-2024-41157

HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

Published Sep 02, 2024

CVE-2024-39816

HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Published Sep 02, 2024

CVE-2024-39775

MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.

Published Sep 02, 2024

CVE-2024-39612

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Published Sep 02, 2024

CVE-2024-38386

HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Published Sep 02, 2024

CVE-2024-38382

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Published Sep 02, 2024

CVE-2024-28044

LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.

Published Sep 02, 2024

CVE-2024-37077

HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Published Jul 02, 2024

CVE-2024-37185

HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Published Jul 02, 2024

CVE-2024-36260

HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Published Jul 02, 2024

CVE-2024-36278

LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

Published Jul 02, 2024

CVE-2024-36243

HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

Published Jul 02, 2024

CVE-2024-37030

HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

Published Jul 02, 2024

CVE-2024-31071

LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

Published Jul 02, 2024

CVE-2024-3759

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

Published May 07, 2024

CVE-2024-3758

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.

Published May 07, 2024

CVE-2024-3757

LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.

Published May 07, 2024

CVE-2024-31078

LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference.

Published May 07, 2024

CVE-2024-23808

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.

Published May 07, 2024

CVE-2024-27217

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

Published May 07, 2024

CVE-2024-29086

LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.

Published Apr 02, 2024

CVE-2024-28951

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

Published Apr 02, 2024

CVE-2024-28226

HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

Published Apr 02, 2024

CVE-2024-24581

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.

Published Apr 02, 2024

CVE-2024-22092

HIGH

in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.

Published Apr 02, 2024

CVE-2024-29074

MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.

Published Apr 02, 2024

CVE-2024-22180

LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

Published Apr 02, 2024

CVE-2024-22098

MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

Published Apr 02, 2024

CVE-2024-22177

LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.

Published Apr 02, 2024

CVE-2024-21834

LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

Published Apr 02, 2024

CVE-2024-21826

MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

Published Mar 04, 2024

CVE-2024-21816

MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.

Published Mar 04, 2024

CVE-2023-49602

LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

Published Mar 04, 2024

CVE-2023-46708

MEDIUM

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

Published Mar 04, 2024