Records whose assigning authority named Openharmony as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-33565kernel_linux_common_modules has a Race Condition vulnerabilityOpenHarmony
CVE-2026-28751filemanagement_storage_service has an improper input validation vulnerabilityOpenHarmony
CVE-2026-28733filemanagement_storage_service has an use after free vulnerabilityOpenHarmony
CVE-2026-27781kernel_liteos_a has an integer overflow vulnerabilityOpenHarmony
CVE-2026-27766multimedia_audio_framework has a Race Condition vulnerabilityOpenHarmony
CVE-2026-27648web_webview has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2026-25850filemanagement_storage_service has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2026-25781kernel_liteos_a has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2026-25110Sensors_medical_sensor has a NULL pointer dereference vulnerabilityOpenHarmony
CVE-2026-24792web_webview has a Race Condition vulnerabilityOpenHarmony
CVE-2026-0639liteos_a has a missing release of memory vulnerabilityOpenHarmony
CVE-2025-6969ability_ability_runtime an improper input validation vulnerabilityOpenHarmony
CVE-2025-52458arkcompiler_ets_runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-41432arkcompiler_ets_runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-27577liteos_a has a race condition vulnerabilityOpenHarmony
CVE-2025-27563security_access_token has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2025-27562communication_dsoftbus has a missing release of memory vulnerabilityOpenHarmony
CVE-2025-27536arkcompiler_ets_runtime has a type confusion vulnerabilityOpenHarmony
CVE-2025-27534arkcompiler_ets_runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-27248ai_neural_network_runtime has a NULL pointer dereference vulnerabilityOpenHarmony
CVE-2025-27247Pasteboard has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2025-27242Ssecurity_component_manager has an improper input vulnerabilityOpenHarmony
CVE-2025-27241multimedia_av_codec has a NULL pointer dereference vulnerabilityOpenHarmony
CVE-2025-27132arkcompiler_ets_runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-27131kernel_liteos_m has an improper input vulnerabilityOpenHarmony
CVE-2025-27128liteos_a has an UAF vulnerabilityOpenHarmony
CVE-2025-26693security_access_token has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2025-26691telephony_call_manager has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2025-26690communication dsoftbus has a NULL pointer vulnerabilityOpenHarmony
CVE-2025-26474communication_ipc an improper input validation vulnerabilityOpenHarmony
CVE-2025-25278liteos_a has a race condition vulnerabilityOpenHarmony
CVE-2025-25277arkcompiler_ets_runtime has a type confusion vulnerabilityOpenHarmony
CVE-2025-25218third_party_mksh has a NULL pointer dereference vulnerabilityOpenHarmony
CVE-2025-25217arkui_ace_enginehas a NULL pointer dereference vulnerabilityOpenHarmony
CVE-2025-25212pasteboard has an improper input vulnerabilityOpenHarmony
CVE-2025-25057third_party_NuttX has a memory leak vulnerabilityOpenHarmony
CVE-2025-25052arkcompiler_ets_runtime has a buffer overflow vulnerabilityOpenHarmony
CVE-2025-24925applications_settings has a missing release of memory vulnerabilityOpenHarmony
CVE-2025-24844communication_dsoftbus has a missing release of memory vulnerabilityOpenHarmony
CVE-2025-24493kernel_liteos_a has a race condition vulnerabilityOpenHarmony
CVE-2025-24309Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-24304arkcompiler_ets_runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-24301Arkcompiler Ets Runtime has an UAF vulnerabilityOpenHarmony
CVE-2025-24298liteos_a has an UAF vulnerabilityOpenHarmony
CVE-2025-23420Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-23418Arkcompiler Ets Runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-23414Arkcompiler Ets Runtime has an UAF vulnerabilityOpenHarmony
CVE-2025-23409Communication Dsoftbus has an UAF vulnerabilityOpenHarmony
CVE-2025-23240Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-23235arkcompiler_ets_runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-23234Arkcompiler Ets Runtime has a buffer overflow vulnerabilityOpenHarmony
CVE-2025-22897Arkcompiler Ets Runtime has a buffer overflow vulnerabilityOpenHarmony
CVE-2025-22886distributeddatamgr_udmf has a memory leak vulnerabilityOpenHarmony
CVE-2025-22851Liteos_A has an integer overflow vulnerabilityOpenHarmony
CVE-2025-22847Arkcompiler Ets Runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-22842arkcompiler_ets_runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-22841Arkcompiler Ets Runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-22837Arkcompiler Ets Runtime has a NULL pointer dereference vulnerabilityOpenHarmony
CVE-2025-22835Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2025-22452arkcompiler_ets_runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-22443Arkcompiler Ets Runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-21098Liteos-A has an insecure storage of sensitive information vulnerabilityOpenHarmony
CVE-2025-21097Arkcompiler Ets Runtime has a NULL pointer dereference vulnerabilityOpenHarmony
CVE-2025-21089Arkcompiler Ets Runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-21084Arkcompiler Ets Runtime has an NULL pointer dereference vulnerabilityOpenHarmony
CVE-2025-21082arkui_ace_engine has a type confusion vulnerabilityOpenHarmony
CVE-2025-20626Arkcompiler Ets Runtime has an UAF vulnerabilityOpenHarmony
CVE-2025-20102arkcompiler_ets_runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-20091Communication Dsoftbus has an UAF vulnerabilityOpenHarmony
CVE-2025-20081Communication Dsoftbus has an UAF vulnerabilityOpenHarmony
CVE-2025-20063arkui_ace_engine has a type confusion vulnerabilityOpenHarmony
CVE-2025-20042Liteos-A has an out of bounds read vulnerabilityOpenHarmony
CVE-2025-20024Arkcompiler Ets Runtime has an integer overflow vulnerabilityOpenHarmony
CVE-2025-20021Arkcompiler Ets Runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2025-20011Communication Dsoftbus has a memory leak vulnerabilityOpenHarmony
CVE-2025-12736multimedia_audio_standard has an insecure storage of sensitive information vulnerabilityOpenHarmony
CVE-2025-0587Arkcompiler Ets Runtime has an integer overflow vulnerabilityOpenHarmony
CVE-2025-0304Liteos_a has an use after free vulnerabilityOpenHarmony
CVE-2025-0303Liteos_a has a buffer overflow vulnerabilityOpenHarmony
CVE-2025-0302Liteos_a has an integer overflow read vulnerabilityOpenHarmony
CVE-2024-9978Liteos_a has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2024-54030Communication_dsoftbus has an UAF vulnerabilityOpenHarmony
CVE-2024-47797Liteos_a has an out-of-bounds Write vulnerabilityOpenHarmony
CVE-2024-47404Liteos_a has a double free vulnerabilityOpenHarmony
CVE-2024-47402Liteos_a has an Out-of-bounds Read vulnerabilityOpenHarmony
CVE-2024-47398Liteos_a has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2024-47137Liteos_a has an out-of-bounds Write vulnerabilityOpenHarmony
CVE-2024-45382Liteos_a has an Out-of-bounds Write vulnerabilityOpenHarmony
CVE-2024-45070Liteos_a has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2024-43697Liteos_a has an Improper Input Validation vulnerabilityOpenHarmony
CVE-2024-43696Liteos_a has an Memory Leak vulnerabilityOpenHarmony
CVE-2024-41160Liteos-A has an use after free vulnerabilityOpenHarmony
CVE-2024-41157Liteos-A has an use after free vulnerabilityOpenHarmony
CVE-2024-39831AccessTokenManager has an use after free vulnerabilityOpenHarmony
CVE-2024-39816Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2024-39806Liteos_a has an out-of-bounds Read vulnerabilityOpenHarmony
CVE-2024-39775Net Manager has an out-of-bounds read permission bypass vulnerabilityOpenHarmony
CVE-2024-39612Background Task Manager has an out-of-bounds read permission bypass vulnerabilityOpenHarmony
CVE-2024-38386Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2024-38382Ability Runtime has an out-of-bounds read permission bypass vulnerabilityOpenHarmony
CVE-2024-3759Hmdfs has a use after free vulnerabilityOpenHarmony
CVE-2024-3758Hmdfs has a heap buffer overflow vulnerabilityOpenHarmony
CVE-2024-3757Arkcompiler runtime has an integer overflow vulnerabilityOpenHarmony
CVE-2024-37185Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2024-37077Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2024-37030Arkcompiler Ets Runtime has a use after free vulnerabilityOpenHarmony
CVE-2024-36278Arkcompiler Ets Runtime has a type confusion vulnerabilityOpenHarmony
CVE-2024-36260Arkcompiler Ets Runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2024-36243Arkcompiler Ets Runtime has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2024-31078Bluetooth Service has a use after free vulnerabilityOpenHarmony
CVE-2024-31071Arkcompiler Ets Runtime has a type confusion vulnerabilityOpenHarmony
CVE-2024-29086Arkcompiler runtime has a stack overflow svulnerabilityOpenHarmony
CVE-2024-29074Telephony has an improper input validation vulnerabilityOpenHarmony
CVE-2024-28951Arkcompiler runtime has a use after free vulnerabilityOpenHarmony
CVE-2024-28226Fs has an improper input validation vulnerabilityOpenHarmony
CVE-2024-28044Liteos-A has an integer overflow vulnerabilityOpenHarmony
CVE-2024-27217MSDP has a use after free vulnerabilityOpenHarmony
CVE-2024-24581Arkcompiler runtime has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2024-23808Arkcompiler ets frontend has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2024-22180Camera has a use after free vulnerabilityOpenHarmony
CVE-2024-22177Audio has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2024-22098AVSession has a use after free vulnerabilityOpenHarmony
CVE-2024-22092Bundlemanager has an authentication bypass vulnerabilityOpenHarmony
CVE-2024-21863Dsoftbus has an improper input validation vulnerabilityOpenHarmony
CVE-2024-21860Dsoftbus has a use after free vulnerabilityOpenHarmony
CVE-2024-21851Dsoftbus has an integer overflow vulnerabilityOpenHarmony
CVE-2024-21845Dsoftbus has an integer overflow vulnerabilityOpenHarmony
CVE-2024-21834Arkui has a type confusion vulnerabilityOpenHarmony
CVE-2024-21826Huks has an insecure storage of sensitive information vulnerabilityOpenHarmony
CVE-2024-21816Background task manager has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2024-12082Ability Runtime has an out-of-bounds read permission bypass vulnerabilityOpenHarmony
CVE-2024-10074Liteos_a has an use after free vulnerabilityOpenHarmony
CVE-2024-0285Dsoftbus has an improper input validation vulnerabilityOpenHarmony
CVE-2023-6045Arkruntime has a type confusion vulnerabilityOpenHarmony
CVE-2023-49602Arkui has a type confusion vulnerabilityOpenHarmony
CVE-2023-49142multimedia audio has a UAF vulnerabilityOpenHarmony
CVE-2023-49135multimedia player has a UAF vulnerabilityOpenHarmony
CVE-2023-49118Dsoftbus has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2023-48360multimedia player has a UAF vulnerabilityOpenHarmony
CVE-2023-47857multimedia camera has a UAF vulnerabilityOpenHarmony
CVE-2023-4753OpenHarmony v3.2.1 and prior version has a system call function usage errorOpenHarmony
CVE-2023-47217Arkruntime has a buffer overflow vulnerabilityOpenHarmony
CVE-2023-47216Liteos-A has a missing release of resource vulnerabilityOpenHarmony
CVE-2023-46708Wlan has a use after free vulnerabilityOpenHarmony
CVE-2023-46705Arkruntime has a type confusion vulnerabilityOpenHarmony
CVE-2023-46100Cert manager has a use of uninitialized resource vulnerabilityOpenHarmony
CVE-2023-45734Dsoftbus has an out-of-bounds write vulnerabilityOpenHarmony
CVE-2023-43756Dsoftbus has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2023-43612Hiview has an improper preservation of permissions vulnerabilityOpenHarmony
CVE-2023-42774Liteos-A has a incorrect default permissions vulnerabilityOpenHarmony
CVE-2023-3116Liteos-A has a incorrect default permissions vulnerabilityOpenHarmony
CVE-2023-25947The bundle management subsystem has a improper input validation when installing a HAP package.OpenHarmony
CVE-2023-25176Pasteboard has an out-of-bounds read vulnerabilityOpenHarmony
CVE-2023-24465Communication Wi-Fi subsystem has a null pointer reference vulnerability when receving external data.OpenHarmony
CVE-2023-22436The kernel subsystem function check_permission_for_set_tokenid has an UAF vulnerability.OpenHarmony
CVE-2023-22301The kernel subsystem hmdfs has a arbitrary memory accessing vulnerability.OpenHarmony
CVE-2023-0083The ArkUI framework subsystem doesn't check the input parameter,causing type confusion and invalid memory access.OpenHarmony
CVE-2023-0036platform_callback_stub in misc subsystem has an authentication bypass vulnerability which allows an "SA relay attack".OpenHarmony
CVE-2023-0035softbus_client_stub in communication subsystem has an authentication bypass vulnerability which allows an "SA relay…OpenHarmony
CVE-2022-45877PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the…OpenHarmony
CVE-2022-45126Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.OpenHarmony
CVE-2022-45118Telephony in communication subsystem sends public events with personal data, but the permission is not set.OpenHarmony
CVE-2022-44455The appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient…OpenHarmony
CVE-2022-43662Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.OpenHarmony
CVE-2022-43495An abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.OpenHarmony
CVE-2022-43451Multiple path traversal in appspawn and nwebspawn services.OpenHarmony
CVE-2022-43449Arbitrary file read via download_server.OpenHarmony
CVE-2022-42488Startup subsystem missed permission validation in param service. An malicious application installed on the device could…OpenHarmony
CVE-2022-42464Kernel memory pool override in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker.…OpenHarmony
CVE-2022-42463Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function.…OpenHarmony
CVE-2022-41802Kernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.OpenHarmony
CVE-2022-41686Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the…OpenHarmony
CVE-2022-38701IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get…OpenHarmony
CVE-2022-38700multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control…OpenHarmony
CVE-2022-38081Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed…OpenHarmony
CVE-2022-38064windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control…OpenHarmony
CVE-2022-36423Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN…OpenHarmony
177 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.