Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenHarmony — Vulnerabilities & Security Advisories 177

All 177 CVE vulnerabilities found in OpenHarmony, with AI-generated Chinese analysis, references, and POCs.

This page aggregates OpenHarmony vulnerability disclosures, focusing on software weaknesses in the operating system ecosystem maintained by the open-source community. It collects data on memory corruption, race conditions, and logic flaws found within kernel and middleware components, covering advisories published over the past three years of active development. Readers can use this resource to track how the project addresses critical security flaws, understand common weakness classes in embedded and IoT environments, and review the vulnerability history for specific OpenHarmony modules. The data highlights the iterative nature of the codebase, showing how patches are issued and integrated into release branches. By examining these entries, developers and security teams can identify recurring patterns in defect types, assess the risk exposure of systems running OpenHarmony, and verify that remediations have been properly applied in their deployment stacks. This aggregation serves as a neutral reference for auditing compliance and evaluating the security maturity of the platform without relying on single-vendor communication channels.

Vendor: OpenHarmony

CVE ID Title CVSS Severity Published
CVE-2024-45382 Liteos_a has an Out-of-bounds Write vulnerability CWE-787 3.3 Low 2024-10-08
CVE-2024-43697 Liteos_a has an Improper Input Validation vulnerability CWE-20 3.3 Low 2024-10-08
CVE-2024-43696 Liteos_a has an Memory Leak vulnerability CWE-401 3.3 Low 2024-10-08
CVE-2024-39831 AccessTokenManager has an use after free vulnerability CWE-416 4.4 Medium 2024-10-08
CVE-2024-39806 Liteos_a has an out-of-bounds Read vulnerability CWE-125 5.5 Medium 2024-10-08
CVE-2024-41160 Liteos-A has an use after free vulnerability CWE-416 8.8 High 2024-09-02
CVE-2024-41157 Liteos-A has an use after free vulnerability CWE-416 8.8 High 2024-09-02
CVE-2024-39816 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.4 High 2024-09-02
CVE-2024-39775 Net Manager has an out-of-bounds read permission bypass vulnerability CWE-125 6.5 Medium 2024-09-02
CVE-2024-39612 Background Task Manager has an out-of-bounds read permission bypass vulnerability CWE-125 5.5 Medium 2024-09-02
CVE-2024-38386 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.4 High 2024-09-02
CVE-2024-38382 Ability Runtime has an out-of-bounds read permission bypass vulnerability CWE-125 5.5 Medium 2024-09-02
CVE-2024-28044 Liteos-A has an integer overflow vulnerability CWE-190 3.3 Low 2024-09-02
CVE-2024-37077 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.2 High 2024-07-02
CVE-2024-37185 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.2 High 2024-07-02
CVE-2024-36260 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability CWE-787 8.2 High 2024-07-02
CVE-2024-36278 Arkcompiler Ets Runtime has a type confusion vulnerability CWE-843 3.3 Low 2024-07-02
CVE-2024-36243 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability CWE-787 8.2 High 2024-07-02
CVE-2024-37030 Arkcompiler Ets Runtime has a use after free vulnerability CWE-416 8.2 High 2024-07-02
CVE-2024-31071 Arkcompiler Ets Runtime has a type confusion vulnerability CWE-843 3.3 Low 2024-07-02
CVE-2024-3759 Hmdfs has a use after free vulnerability CWE-416 6.5 Medium 2024-05-07
CVE-2024-3758 Hmdfs has a heap buffer overflow vulnerability CWE-122 6.5 Medium 2024-05-07
CVE-2024-3757 Arkcompiler runtime has an integer overflow vulnerability CWE-190 3.3 Low 2024-05-07
CVE-2024-31078 Bluetooth Service has a use after free vulnerability CWE-476 3.3 Low 2024-05-07
CVE-2024-23808 Arkcompiler ets frontend has an out-of-bounds read vulnerability CWE-125 5.2 Medium 2024-05-07
CVE-2024-27217 MSDP has a use after free vulnerability CWE-416 6.5 Medium 2024-05-07
CVE-2024-29086 Arkcompiler runtime has a stack overflow svulnerability CWE-770 3.3 Low 2024-04-02
CVE-2024-28951 Arkcompiler runtime has a use after free vulnerability CWE-416 5.5 Medium 2024-04-02
CVE-2024-28226 Fs has an improper input validation vulnerability CWE-20 8.1 High 2024-04-02
CVE-2024-24581 Arkcompiler runtime has an out-of-bounds write vulnerability CWE-787 6.5 Medium 2024-04-02

All 177 known CVE vulnerabilities affecting OpenHarmony with full Chinese analysis, references, and POCs where available.