8.8
CVE-2024-41160 - Liteos-A has an use after free vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
8.8
CVE-2024-41157 - Liteos-A has an use after free vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
8.4
CVE-2024-39816 - Arkcompiler Ets Runtime has an out-of-bounds write vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
6.5
CVE-2024-39775 - Net Manager has an out-of-bounds read permission bypass vulnerability
in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.
5.5
CVE-2024-39612 - Background Task Manager has an out-of-bounds read permission bypass vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
8.4
CVE-2024-38386 - Arkcompiler Ets Runtime has an out-of-bounds write vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
5.5
CVE-2024-38382 - Ability Runtime has an out-of-bounds read permission bypass vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
3.3
CVE-2024-28044 - Liteos-A has an integer overflow vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.
7.5
CVE-2024-20089 -
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
4.4
CVE-2024-20088 -
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932099; Issue ID: MSV-1543.