Openatom maintains a highly focused portfolio centered on open-source operating systems and kernel implementations, most prominently OpenHarmony and OpenEuler, that are embedded across a large installed base in mobile and server deployments despite a narrow product count. The vendor's vulnerability exposure recurs through memory-safety and input-handling weakness classes including out-of-bounds reads and writes, use-after-free conditions, improper input validation, and NULL-pointer dereferences, reflecting the low-level systems programming inherent to kernel and OS development. These disclosures cluster around the native codebases of its flagship products and represent structural weaknesses typical of systems software rather than application-level defects. Defenders should inventory deployments of OpenHarmony and OpenEuler systems in their environment and treat OS-level patches as part of their standard supply-chain management; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openatom over time
Signals from CVEs in this vendor scope (166 CVEs).
166 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33643CRITICAL An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds r | Aug 10, 2022 | 9.1 | 32 | NO | NO |
CVE-2021-33640CRITICAL After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t | Dec 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-36260CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2021-33644HIGH An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds r | Aug 10, 2022 | 8.1 | 27 | NO | NO |
CVE-2025-27128HIGH in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | Aug 11, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-24298HIGH in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | Aug 11, 2025 | 7.8 | 26 | NO | NO |
CVE-2024-37185CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-37077CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-37030CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-36243CRITICAL in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write. | Jul 2, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (166 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openatom.
Media articles that mention a CVE ID that affects a product developed by Openatom — matched by CVE ID, not by vendor name.