Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenHarmony — Vulnerabilities & Security Advisories 177

All 177 CVE vulnerabilities found in OpenHarmony, with AI-generated Chinese analysis, references, and POCs.

This page aggregates OpenHarmony vulnerability disclosures, focusing on software weaknesses in the operating system ecosystem maintained by the open-source community. It collects data on memory corruption, race conditions, and logic flaws found within kernel and middleware components, covering advisories published over the past three years of active development. Readers can use this resource to track how the project addresses critical security flaws, understand common weakness classes in embedded and IoT environments, and review the vulnerability history for specific OpenHarmony modules. The data highlights the iterative nature of the codebase, showing how patches are issued and integrated into release branches. By examining these entries, developers and security teams can identify recurring patterns in defect types, assess the risk exposure of systems running OpenHarmony, and verify that remediations have been properly applied in their deployment stacks. This aggregation serves as a neutral reference for auditing compliance and evaluating the security maturity of the platform without relying on single-vendor communication channels.

Vendor: OpenHarmony

CVE ID Title CVSS Severity Published
CVE-2024-22092 Bundlemanager has an authentication bypass vulnerability CWE-290 7.7 High 2024-04-02
CVE-2024-29074 Telephony has an improper input validation vulnerability CWE-20 6.5 Medium 2024-04-02
CVE-2024-22180 Camera has a use after free vulnerability CWE-416 3.3 Low 2024-04-02
CVE-2024-22098 AVSession has a use after free vulnerability CWE-416 6.5 Medium 2024-04-02
CVE-2024-22177 Audio has an improper preservation of permissions vulnerability CWE-281 3.3 Low 2024-04-02
CVE-2024-21834 Arkui has a type confusion vulnerability CWE-843 3.3 Low 2024-04-02
CVE-2024-21826 Huks has an insecure storage of sensitive information vulnerability CWE-922 4.3 Medium 2024-03-04
CVE-2024-21816 Background task manager has an improper preservation of permissions vulnerability CWE-281 4.0 Medium 2024-03-04
CVE-2023-49602 Arkui has a type confusion vulnerability CWE-843 2.9 Low 2024-03-04
CVE-2023-46708 Wlan has a use after free vulnerability CWE-416 4.3 Medium 2024-03-04
CVE-2023-25176 Pasteboard has an out-of-bounds read vulnerability CWE-125 2.9 Low 2024-03-04
CVE-2024-21863 Dsoftbus has an improper input validation vulnerability CWE-20 4.7 Medium 2024-02-02
CVE-2024-21851 Dsoftbus has an integer overflow vulnerability CWE-190 2.9 Low 2024-02-02
CVE-2024-0285 Dsoftbus has an improper input validation vulnerability CWE-20 4.7 Medium 2024-02-02
CVE-2023-45734 Dsoftbus has an out-of-bounds write vulnerability CWE-787 4.2 Medium 2024-02-02
CVE-2024-21860 Dsoftbus has a use after free vulnerability CWE-416 8.2 High 2024-02-02
CVE-2024-21845 Dsoftbus has an integer overflow vulnerability CWE-190 2.9 Low 2024-02-02
CVE-2023-49118 Dsoftbus has an out-of-bounds read vulnerability CWE-125 2.9 Low 2024-02-02
CVE-2023-43756 Dsoftbus has an out-of-bounds read vulnerability CWE-125 2.9 Low 2024-02-02
CVE-2023-49142 multimedia audio has a UAF vulnerability CWE-416 4.0 Medium 2024-01-02
CVE-2023-49135 multimedia player has a UAF vulnerability CWE-416 4.0 Medium 2024-01-02
CVE-2023-48360 multimedia player has a UAF vulnerability CWE-416 4.0 Medium 2024-01-02
CVE-2023-47857 multimedia camera has a UAF vulnerability CWE-416 4.0 Medium 2024-01-02
CVE-2023-47216 Liteos-A has a missing release of resource vulnerability CWE-772 2.9 Low 2024-01-02
CVE-2023-47217 Arkruntime has a buffer overflow vulnerability CWE-120 4.0 Medium 2023-11-20
CVE-2023-46100 Cert manager has a use of uninitialized resource vulnerability CWE-908 6.2 Medium 2023-11-20
CVE-2023-42774 Liteos-A has a incorrect default permissions vulnerability CWE-276 6.2 Medium 2023-11-20
CVE-2023-6045 Arkruntime has a type confusion vulnerability CWE-843 5.9 Medium 2023-11-20
CVE-2023-46705 Arkruntime has a type confusion vulnerability CWE-843 6.2 Medium 2023-11-20
CVE-2023-43612 Hiview has an improper preservation of permissions vulnerability CWE-281 8.4 High 2023-11-20

All 177 known CVE vulnerabilities affecting OpenHarmony with full Chinese analysis, references, and POCs where available.