Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenHarmony — Vulnerabilities & Security Advisories 177

Browse all 177 CVE security advisories affecting OpenHarmony. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenHarmony is an open-source operating system designed for distributed scenarios across smart devices, IoT, and industrial applications. Its architecture emphasizes modularity and scalability, allowing developers to tailor the system for diverse hardware constraints. Historically, the project has faced 167 recorded Common Vulnerabilities and Exposures (CVEs), with recurring issues primarily involving buffer overflows, use-after-free errors, and improper input validation. These flaws often lead to remote code execution or privilege escalation, particularly within the device communication and permission management modules. While no single catastrophic incident has defined its history, the high volume of CVEs highlights challenges in maintaining rigorous security standards across its fragmented ecosystem. The project relies on community-driven patches and formal verification efforts to mitigate risks, though the complexity of its distributed nature continues to present significant attack surface challenges for security researchers and administrators alike.

Top products by OpenHarmony: OpenHarmony
CVE ID Title CVSS Severity Published
CVE-2024-22092 Bundlemanager has an authentication bypass vulnerability — OpenHarmony CWE-290 7.7 High 2024-04-02
CVE-2024-29074 Telephony has an improper input validation vulnerability — OpenHarmony CWE-20 6.5 Medium 2024-04-02
CVE-2024-22180 Camera has a use after free vulnerability — OpenHarmony CWE-416 3.3 Low 2024-04-02
CVE-2024-22098 AVSession has a use after free vulnerability — OpenHarmony CWE-416 6.5 Medium 2024-04-02
CVE-2024-22177 Audio has an improper preservation of permissions vulnerability — OpenHarmony CWE-281 3.3 Low 2024-04-02
CVE-2024-21834 Arkui has a type confusion vulnerability — OpenHarmony CWE-843 3.3 Low 2024-04-02
CVE-2024-21826 Huks has an insecure storage of sensitive information vulnerability — OpenHarmony CWE-922 4.3 Medium 2024-03-04
CVE-2024-21816 Background task manager has an improper preservation of permissions vulnerability — OpenHarmony CWE-281 4.0 Medium 2024-03-04
CVE-2023-49602 Arkui has a type confusion vulnerability — OpenHarmony CWE-843 2.9 Low 2024-03-04
CVE-2023-46708 Wlan has a use after free vulnerability — OpenHarmony CWE-416 4.3 Medium 2024-03-04
CVE-2023-25176 Pasteboard has an out-of-bounds read vulnerability — OpenHarmony CWE-125 2.9 Low 2024-03-04
CVE-2024-21863 Dsoftbus has an improper input validation vulnerability — OpenHarmony CWE-20 4.7 Medium 2024-02-02
CVE-2024-21851 Dsoftbus has an integer overflow vulnerability — OpenHarmony CWE-190 2.9 Low 2024-02-02
CVE-2024-0285 Dsoftbus has an improper input validation vulnerability — OpenHarmony CWE-20 4.7 Medium 2024-02-02
CVE-2023-45734 Dsoftbus has an out-of-bounds write vulnerability — OpenHarmony CWE-787 4.2 Medium 2024-02-02
CVE-2024-21860 Dsoftbus has a use after free vulnerability — OpenHarmony CWE-416 8.2 High 2024-02-02
CVE-2024-21845 Dsoftbus has an integer overflow vulnerability — OpenHarmony CWE-190 2.9 Low 2024-02-02
CVE-2023-49118 Dsoftbus has an out-of-bounds read vulnerability — OpenHarmony CWE-125 2.9 Low 2024-02-02
CVE-2023-43756 Dsoftbus has an out-of-bounds read vulnerability — OpenHarmony CWE-125 2.9 Low 2024-02-02
CVE-2023-49142 multimedia audio has a UAF vulnerability — OpenHarmony CWE-416 4.0 Medium 2024-01-02
CVE-2023-49135 multimedia player has a UAF vulnerability — OpenHarmony CWE-416 4.0 Medium 2024-01-02
CVE-2023-48360 multimedia player has a UAF vulnerability — OpenHarmony CWE-416 4.0 Medium 2024-01-02
CVE-2023-47857 multimedia camera has a UAF vulnerability — OpenHarmony CWE-416 4.0 Medium 2024-01-02
CVE-2023-47216 Liteos-A has a missing release of resource vulnerability — OpenHarmony CWE-772 2.9 Low 2024-01-02
CVE-2023-47217 Arkruntime has a buffer overflow vulnerability — OpenHarmony CWE-120 4.0 Medium 2023-11-20
CVE-2023-46100 Cert manager has a use of uninitialized resource vulnerability — OpenHarmony CWE-908 6.2 Medium 2023-11-20
CVE-2023-42774 Liteos-A has a incorrect default permissions vulnerability — OpenHarmony CWE-276 6.2 Medium 2023-11-20
CVE-2023-6045 Arkruntime has a type confusion vulnerability — OpenHarmony CWE-843 5.9 Medium 2023-11-20
CVE-2023-46705 Arkruntime has a type confusion vulnerability — OpenHarmony CWE-843 6.2 Medium 2023-11-20
CVE-2023-43612 Hiview has an improper preservation of permissions vulnerability — OpenHarmony CWE-281 8.4 High 2023-11-20

This page lists every published CVE security advisory associated with OpenHarmony. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.