Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenHarmony — Vulnerabilities & Security Advisories 177

All 177 CVE vulnerabilities found in OpenHarmony, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security weaknesses affecting the OpenHarmony project, an open-source operating system developed by the OpenAtom Foundation. It compiles a diverse range of Common Weakness Enumeration (CWE) entries associated with OpenHarmony, covering critical security flaws identified through both internal development processes and external community disclosures. The dataset encompasses vulnerabilities reported from the initial release of OpenHarmony through to the most recent updates, ensuring a historical perspective on the ecosystem's security posture. By navigating this resource, researchers and developers can efficiently track advisory patterns from the OpenHarmony vendor, gaining insight into how specific issues are acknowledged and mitigated over time. Users can also explore the prevalence of particular weakness classes within the codebase to understand common architectural or implementation errors. Furthermore, the aggregation allows for a detailed examination of a specific product’s vulnerability history, highlighting trends in security maintenance and the evolving complexity of the software stack. This centralized view supports informed risk assessment and helps stakeholders prioritize remediation efforts based on historical data and current threat landscapes. The information is organized to facilitate quick reference for security analysts, system integrators, and end-users who require a clear understanding of the known defects in OpenHarmony distributions.

Vendor: OpenHarmony

CVE IDTitleCVSSSeverityPublished
CVE-2024-45382 Liteos_a has an Out-of-bounds Write vulnerability CWE-787 3.3 Low2024-10-08
CVE-2024-43697 Liteos_a has an Improper Input Validation vulnerability CWE-20 3.3 Low2024-10-08
CVE-2024-43696 Liteos_a has an Memory Leak vulnerability CWE-401 3.3 Low2024-10-08
CVE-2024-39831 AccessTokenManager has an use after free vulnerability CWE-416 4.4 Medium2024-10-08
CVE-2024-39806 Liteos_a has an out-of-bounds Read vulnerability CWE-125 5.5 Medium2024-10-08
CVE-2024-41160 Liteos-A has an use after free vulnerability CWE-416 8.8 High2024-09-02
CVE-2024-41157 Liteos-A has an use after free vulnerability CWE-416 8.8 High2024-09-02
CVE-2024-39816 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.4 High2024-09-02
CVE-2024-39775 Net Manager has an out-of-bounds read permission bypass vulnerability CWE-125 6.5 Medium2024-09-02
CVE-2024-39612 Background Task Manager has an out-of-bounds read permission bypass vulnerability CWE-125 5.5 Medium2024-09-02
CVE-2024-38386 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.4 High2024-09-02
CVE-2024-38382 Ability Runtime has an out-of-bounds read permission bypass vulnerability CWE-125 5.5 Medium2024-09-02
CVE-2024-28044 Liteos-A has an integer overflow vulnerability CWE-190 3.3 Low2024-09-02
CVE-2024-37077 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.2 High2024-07-02
CVE-2024-37185 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.2 High2024-07-02
CVE-2024-36260 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.2 High2024-07-02
CVE-2024-36278 Arkcompiler Ets Runtime has a type confusion vulnerability CWE-843 3.3 Low2024-07-02
CVE-2024-36243 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability CWE-787 8.2 High2024-07-02
CVE-2024-37030 Arkcompiler Ets Runtime has a use after free vulnerability CWE-416 8.2 High2024-07-02
CVE-2024-31071 Arkcompiler Ets Runtime has a type confusion vulnerability CWE-843 3.3 Low2024-07-02
CVE-2024-3759 Hmdfs has a use after free vulnerability CWE-416 6.5 Medium2024-05-07
CVE-2024-3758 Hmdfs has a heap buffer overflow vulnerability CWE-122 6.5 Medium2024-05-07
CVE-2024-3757 Arkcompiler runtime has an integer overflow vulnerability CWE-190 3.3 Low2024-05-07
CVE-2024-31078 Bluetooth Service has a use after free vulnerability CWE-476 3.3 Low2024-05-07
CVE-2024-23808 Arkcompiler ets frontend has an out-of-bounds read vulnerability CWE-125 5.2 Medium2024-05-07
CVE-2024-27217 MSDP has a use after free vulnerability CWE-416 6.5 Medium2024-05-07
CVE-2024-29086 Arkcompiler runtime has a stack overflow svulnerability CWE-770 3.3 Low2024-04-02
CVE-2024-28951 Arkcompiler runtime has a use after free vulnerability CWE-416 5.5 Medium2024-04-02
CVE-2024-28226 Fs has an improper input validation vulnerability CWE-20 8.1 High2024-04-02
CVE-2024-24581 Arkcompiler runtime has an out-of-bounds write vulnerability CWE-787 6.5 Medium2024-04-02

All 177 known CVE vulnerabilities affecting OpenHarmony with full Chinese analysis, references, and POCs where available.