
CVE-2025-27562 – communication_dsoftbus has a missing release of memory vulnerability
https://notcve.org/view.php?id=CVE-2025-27562
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. En OpenHarmony v5.0.3 y versiones anteriores se permite que un atacante local cometa un ataque DOS mediante la falta de liberación de memoria. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-401: Missing Release of Memory after Effective Lifetime •

CVE-2025-27128 – liteos_a has an UAF vulnerability
https://notcve.org/view.php?id=CVE-2025-27128
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. En OpenHarmony v5.0.3 y versiones anteriores se permite a un atacante local la ejecución de código arbitrario en tcb mediante el use after free. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-416: Use After Free •

CVE-2025-25212 – pasteboard has an improper input vulnerability
https://notcve.org/view.php?id=CVE-2025-25212
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input. En OpenHarmony v5.0.3 y versiones anteriores se permite que un atacante local cometa un ataque DOS mediante una entrada incorrecta. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-20: Improper Input Validation •

CVE-2025-24844 – communication_dsoftbus has a missing release of memory vulnerability
https://notcve.org/view.php?id=CVE-2025-24844
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. En OpenHarmony v5.0.3 y versiones anteriores se permite que un atacante local cometa un ataque DOS mediante la falta de liberación de memoria. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-401: Missing Release of Memory after Effective Lifetime •

CVE-2025-27536 – arkcompiler_ets_runtime has a type confusion vulnerability
https://notcve.org/view.php?id=CVE-2025-27536
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion. En OpenHarmony v5.0.3 y versiones anteriores se permite que un atacante local provoque un DOS a través de una confusión de tipos. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2025-26690 – communication dsoftbus has a NULL pointer vulnerability
https://notcve.org/view.php?id=CVE-2025-26690
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. En OpenHarmony v5.0.3 y versiones anteriores se permite que un atacante local cometa un ataque DOS mediante la desreferencia de un puntero NULL. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-476: NULL Pointer Dereference •

CVE-2025-24925 – applications_settings has a missing release of memory vulnerability
https://notcve.org/view.php?id=CVE-2025-24925
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. En OpenHarmony v5.0.3 y versiones anteriores se permite que un atacante local cometa un ataque DOS mediante la falta de liberación de memoria. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-401: Missing Release of Memory after Effective Lifetime •

CVE-2025-24298 – liteos_a has an UAF vulnerability
https://notcve.org/view.php?id=CVE-2025-24298
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. En OpenHarmony v5.0.3 y versiones anteriores se permite a un atacante local la ejecución de código arbitrario en tcb mediante el use after free. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-07.md • CWE-416: Use After Free •

CVE-2025-25278 – liteos_a has a race condition vulnerability
https://notcve.org/view.php?id=CVE-2025-25278
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. En OpenHarmony v5.0.3 y versiones anteriores se permite a un atacante local la ejecución de código arbitrario en tcb a través de una condición de ejecución. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-08.md • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2025-27577 – liteos_a has a race condition vulnerability
https://notcve.org/view.php?id=CVE-2025-27577
11 Aug 2025 — in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. En OpenHarmony v5.0.3 y versiones anteriores se permite a un atacante local la ejecución de código arbitrario en tcb a través de una condición de ejecución. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2025/2025-08.md • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •