
CVE-2022-42463 – Softbus_server in communication subsystem has a authenication bypass vulnerability in a callback handler function. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary co ...
https://notcve.org/view.php?id=CVE-2022-42463
14 Oct 2022 — OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands. OpenHarmony versiones v3.1.2 y versiones anteriores, presentan una vulnerabilidad de omisión de autentificación en una función de callback handler de Softbus_server en el subsistema de comunicación. Los atacant... • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-10.md • CWE-287: Improper Authentication •

CVE-2022-41686 – Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The proc ...
https://notcve.org/view.php?id=CVE-2022-41686
14 Oct 2022 — OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption. OpenHarmony versiones v3.1.2 y versi... • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-10.md • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •

CVE-2022-42488 – Startup subsystem missed permission validation in param service. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.
https://notcve.org/view.php?id=CVE-2022-42488
14 Oct 2022 — OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services. OpenHarmony versiones v3.1.2 y versiones anteriores, presentan una vulnerabilidad de Falta de comprobación de permisos en el servicio param del subsistema de inicio. Una aplicación maliciosa instalada en el disposi... • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-10.md • CWE-287: Improper Authentication CWE-862: Missing Authorization •

CVE-2022-38701 – IPC in communication subsystem has a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
https://notcve.org/view.php?id=CVE-2022-38701
09 Sep 2022 — OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information. OpenHarmony versiones v3.1.2 y anteriores, presentan una vulnerabilidad de desbordamiento de pila. Los atacantes locales pueden desencadenar un desbordamiento de pila y conseguir información confidencial de la red • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVE-2022-38081 – Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
https://notcve.org/view.php?id=CVE-2022-38081
09 Sep 2022 — OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system. OpenHarmony versiones v3.1.2 y anteriores, presentan una vulnerabilidad de evasión de permisos. Para aprovechar esta debilidad, los atacantes necesitan otra vulnerabilidad para obtener el sistema • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md • CWE-287: Improper Authentication CWE-305: Authentication Bypass by Primary Weakness •

CVE-2022-38700 – multimedia subsystem has a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
https://notcve.org/view.php?id=CVE-2022-38700
09 Sep 2022 — OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service. OpenHarmony versiones v3.1.1 y anteriores, presentan una vulnerabilidad de omisión de permisos. Los atacantes locales pueden omitir un control de permisos y conseguir el control del servicio de la cámara • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md • CWE-287: Improper Authentication CWE-305: Authentication Bypass by Primary Weakness •

CVE-2022-38064 – windowmanager in window subsystem has a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
https://notcve.org/view.php?id=CVE-2022-38064
09 Sep 2022 — OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information. OpenHarmony versiones v3.1.2 y anteriores, presentan una vulnerabilidad de omisión de permisos. Los atacantes locales pueden omitir el control de permisos y conseguir información confidencial • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md • CWE-287: Improper Authentication CWE-305: Authentication Bypass by Primary Weakness •

CVE-2022-36423 – Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.
https://notcve.org/view.php?id=CVE-2022-36423
09 Sep 2022 — OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices. OpenHarmony versiones v3.1.2 y anteriores, presentan una configuración incorrecta de la biblioteca cJSON, que conlleva a una vulnerabilidad de desbordamiento de pila durante el análisis recursivo. Los atacantes de la LAN pueden conllevar a un ataque DoS a todos los dispositivos de la red • https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md • CWE-16: Configuration CWE-787: Out-of-bounds Write •