Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenHarmony — Vulnerabilities & Security Advisories 177

Browse all 177 CVE security advisories affecting OpenHarmony. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenHarmony is an open-source operating system designed for distributed scenarios across smart devices, IoT, and industrial applications. Its architecture emphasizes modularity and scalability, allowing developers to tailor the system for diverse hardware constraints. Historically, the project has faced 167 recorded Common Vulnerabilities and Exposures (CVEs), with recurring issues primarily involving buffer overflows, use-after-free errors, and improper input validation. These flaws often lead to remote code execution or privilege escalation, particularly within the device communication and permission management modules. While no single catastrophic incident has defined its history, the high volume of CVEs highlights challenges in maintaining rigorous security standards across its fragmented ecosystem. The project relies on community-driven patches and formal verification efforts to mitigate risks, though the complexity of its distributed nature continues to present significant attack surface challenges for security researchers and administrators alike.

Top products by OpenHarmony: OpenHarmony
CVE ID Title CVSS Severity Published
CVE-2024-45382 Liteos_a has an Out-of-bounds Write vulnerability — OpenHarmony CWE-787 3.3 Low 2024-10-08
CVE-2024-43697 Liteos_a has an Improper Input Validation vulnerability — OpenHarmony CWE-20 3.3 Low 2024-10-08
CVE-2024-43696 Liteos_a has an Memory Leak vulnerability — OpenHarmony CWE-401 3.3 Low 2024-10-08
CVE-2024-39831 AccessTokenManager has an use after free vulnerability — OpenHarmony CWE-416 4.4 Medium 2024-10-08
CVE-2024-39806 Liteos_a has an out-of-bounds Read vulnerability — OpenHarmony CWE-125 5.5 Medium 2024-10-08
CVE-2024-41160 Liteos-A has an use after free vulnerability — OpenHarmony CWE-416 8.8 High 2024-09-02
CVE-2024-41157 Liteos-A has an use after free vulnerability — OpenHarmony CWE-416 8.8 High 2024-09-02
CVE-2024-39816 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability — OpenHarmony CWE-787 8.4 High 2024-09-02
CVE-2024-39775 Net Manager has an out-of-bounds read permission bypass vulnerability — OpenHarmony CWE-125 6.5 Medium 2024-09-02
CVE-2024-39612 Background Task Manager has an out-of-bounds read permission bypass vulnerability — OpenHarmony CWE-125 5.5 Medium 2024-09-02
CVE-2024-38386 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability — OpenHarmony CWE-787 8.4 High 2024-09-02
CVE-2024-38382 Ability Runtime has an out-of-bounds read permission bypass vulnerability — OpenHarmony CWE-125 5.5 Medium 2024-09-02
CVE-2024-28044 Liteos-A has an integer overflow vulnerability — OpenHarmony CWE-190 3.3 Low 2024-09-02
CVE-2024-37077 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability — OpenHarmony CWE-787 8.2 High 2024-07-02
CVE-2024-37185 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability — OpenHarmony CWE-787 8.2 High 2024-07-02
CVE-2024-36260 Arkcompiler Ets Runtime has an out-of-bounds write vulnerability — OpenHarmony CWE-787 8.2 High 2024-07-02
CVE-2024-36278 Arkcompiler Ets Runtime has a type confusion vulnerability — OpenHarmony CWE-843 3.3 Low 2024-07-02
CVE-2024-36243 Arkcompiler Ets Runtime has an out-of-bounds read vulnerability — OpenHarmony CWE-787 8.2 High 2024-07-02
CVE-2024-37030 Arkcompiler Ets Runtime has a use after free vulnerability — OpenHarmony CWE-416 8.2 High 2024-07-02
CVE-2024-31071 Arkcompiler Ets Runtime has a type confusion vulnerability — OpenHarmony CWE-843 3.3 Low 2024-07-02
CVE-2024-3759 Hmdfs has a use after free vulnerability — OpenHarmony CWE-416 6.5 Medium 2024-05-07
CVE-2024-3758 Hmdfs has a heap buffer overflow vulnerability — OpenHarmony CWE-122 6.5 Medium 2024-05-07
CVE-2024-3757 Arkcompiler runtime has an integer overflow vulnerability — OpenHarmony CWE-190 3.3 Low 2024-05-07
CVE-2024-31078 Bluetooth Service has a use after free vulnerability — OpenHarmony CWE-476 3.3 Low 2024-05-07
CVE-2024-23808 Arkcompiler ets frontend has an out-of-bounds read vulnerability — OpenHarmony CWE-125 5.2 Medium 2024-05-07
CVE-2024-27217 MSDP has a use after free vulnerability — OpenHarmony CWE-416 6.5 Medium 2024-05-07
CVE-2024-29086 Arkcompiler runtime has a stack overflow svulnerability — OpenHarmony CWE-770 3.3 Low 2024-04-02
CVE-2024-28951 Arkcompiler runtime has a use after free vulnerability — OpenHarmony CWE-416 5.5 Medium 2024-04-02
CVE-2024-28226 Fs has an improper input validation vulnerability — OpenHarmony CWE-20 8.1 High 2024-04-02
CVE-2024-24581 Arkcompiler runtime has an out-of-bounds write vulnerability — OpenHarmony CWE-787 6.5 Medium 2024-04-02

This page lists every published CVE security advisory associated with OpenHarmony. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.