Openharmony

Vendor:

First CVE: Sep 9, 2022 · Active for 3 years

156
Total CVEs
More Total CVEs than 99% of tracked products
31.2
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openharmony over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2022
3 years ago
Most Recent CVE
Mar 16, 2026
130 days ago

CVE Severity & Scoring

Openharmony156 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local144 (92.3%)
Network9 (5.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (1.9%)
Attack Complexity
Low152 (97.4%)
High4 (2.6%)
Unknown0 (0.0%)
User Interaction
None155 (99.4%)
Unknown0 (0.0%)
Required1 (0.6%)
Privileges Required
Low142 (91.0%)
High1 (0.6%)
None13 (8.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (156 CVEs).

156 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
Jul 2, 20249.827NONO
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
Aug 11, 20257.826NONO
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
Aug 11, 20257.826NONO
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
Jul 2, 20249.826NONO
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
Jul 2, 20249.826NONO
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.
Jul 2, 20249.826NONO
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.
Jul 2, 20249.826NONO
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kern
Jan 9, 20237.826NONO
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
Aug 11, 20257.025NONO
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.
Apr 2, 20248.825NONO

Exploit Exposure

Signals from CVEs in this product scope (156 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (156 CVEs).

Media Mentions

Signals from CVEs in this product scope (156 CVEs).

Top CNAs Publishing CVEs For Openharmony

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.1.047.00.2%00
5.0.366.30.2%00
4.0.125.50.1%00
4.096.30.2%00