3.3
CVE-2025-21089 - Arkcompiler Ets Runtime has an out-of-bounds read vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
3.8
CVE-2025-21084 - Arkcompiler Ets Runtime has an NULL pointer dereference vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios.
3.8
CVE-2025-20626 - Arkcompiler Ets Runtime has an UAF vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
3.8
CVE-2025-20091 - Communication Dsoftbus has an UAF vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
3.8
CVE-2025-20081 - Communication Dsoftbus has an UAF vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
5.5
CVE-2025-20042 - Liteos-A has an out of bounds read vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.
3.8
CVE-2025-20024 - Arkcompiler Ets Runtime has an integer overflow vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only in restricted scenarios.
3.3
CVE-2025-20021 - Arkcompiler Ets Runtime has an out-of-bounds read vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
3.3
CVE-2025-20011 - Communication Dsoftbus has a memory leak vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
3.8
CVE-2025-0587 - Arkcompiler Ets Runtime has an integer overflow vulnerability
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only in restricted scenarios.