ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-45126
+1 in the same advisory: …43662
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime.

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

NVD description · AI analysis pending
7.8<1%
  • openharmony openharmony
CVE-2022-44455
+3 in the same advisory: …45118 …45877 …41802
The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficien

The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

NVD description · AI analysis pending
7.8
group max
<1%
  • openharmony openharmony
CVE-2022-43495
+2 in the same advisory: …43451 …43449
OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network.

OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network. Network attakcers can send an abonormal packet when joining a network, cause a nullptr reference and device reboot.

NVD description · AI analysis pending
7.5
group max
<1%
  • openharmony openharmony
CVE-2022-42463
+3 in the same advisory: …42464 …42488 …41686
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem.

OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.

NVD description · AI analysis pending
8.8
group max
<1%
  • openharmony openharmony
CVE-2022-38700
+4 in the same advisory: …36423 …38081 …38064 …38701
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability.

OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.

NVD description · AI analysis pending
8.8
group max
<1%
  • openharmony openharmony