Skip to main content

Vendor/product archive

openatom / openharmony CVEs

Beta · best-effort

156 CVEs tagged to openatom / openharmony0 Critical, 27 High, 57 Medium, 72 Low, 0 Unrated.

CVE-2026-0639

Published Mar 16, 2026

in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6969

Published Mar 16, 2026

in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52458

Published Mar 16, 2026

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited onl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-41432

Published Mar 16, 2026

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited onl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-26474

Published Mar 16, 2026

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25277

Published Mar 16, 2026

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12736

Published Mar 16, 2026

in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27577

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27562

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-27536

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-27128

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26690

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-25278

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25212

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24925

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24844

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24298

Published Aug 11, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27563

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-27247

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27242

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-27131

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-26693

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-26691

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25217

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24493

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 156 CVEsPage 1 of 7