
CVE-2024-21845 – Dsoftbus has an integer overflow vulnerability
https://notcve.org/view.php?id=CVE-2024-21845
02 Feb 2024 — in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow. Las versiones de OpenHarmony v4.0.0 y versiones anteriores permiten que un atacante local provoque un desbordamiento en la región Heap a través de un desbordamiento de enteros. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-02.md • CWE-190: Integer Overflow or Wraparound •

CVE-2023-49118 – Dsoftbus has an out-of-bounds read vulnerability
https://notcve.org/view.php?id=CVE-2023-49118
02 Feb 2024 — in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read. Las versiones de OpenHarmony v3.2.4 y versiones anteriores permiten que un atacante local provoque una fuga de información a través de lectura fuera de los límites. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-02.md • CWE-125: Out-of-bounds Read •

CVE-2023-43756 – Dsoftbus has an out-of-bounds read vulnerability
https://notcve.org/view.php?id=CVE-2023-43756
02 Feb 2024 — in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read. Las versiones de OpenHarmony v3.2.4 y versiones anteriores permiten que un atacante local provoque una fuga de información a través de lectura fuera de los límites. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-02.md • CWE-125: Out-of-bounds Read •

CVE-2023-49142 – multimedia audio has a UAF vulnerability
https://notcve.org/view.php?id=CVE-2023-49142
02 Jan 2024 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque una falla del audio multimedia al modificar un puntero liberado. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-01.md • CWE-416: Use After Free •

CVE-2023-49135 – multimedia player has a UAF vulnerability
https://notcve.org/view.php?id=CVE-2023-49135
02 Jan 2024 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque la caída del reproductor multimedia modificando un puntero liberado. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-01.md • CWE-416: Use After Free •

CVE-2023-48360 – multimedia player has a UAF vulnerability
https://notcve.org/view.php?id=CVE-2023-48360
02 Jan 2024 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque la caída del reproductor multimedia modificando un puntero liberado. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-01.md • CWE-416: Use After Free •

CVE-2023-47857 – multimedia camera has a UAF vulnerability
https://notcve.org/view.php?id=CVE-2023-47857
02 Jan 2024 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque el bloqueo de la cámara multimedia modificando un puntero liberado. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-01.md • CWE-416: Use After Free •

CVE-2023-47216 – Liteos-A has a missing release of resource vulnerability
https://notcve.org/view.php?id=CVE-2023-47216
02 Jan 2024 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local haga que DOS ocupe todos los recursos • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-01.md • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2023-47217 – Arkruntime has a buffer overflow vulnerability
https://notcve.org/view.php?id=CVE-2023-47217
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque DOS a través de un desbordamiento del búfer. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-46100 – Cert manager has a use of uninitialized resource vulnerability
https://notcve.org/view.php?id=CVE-2023-46100
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local obtenga información confidencial del búfer mediante el uso de recursos no inicializados. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-908: Use of Uninitialized Resource •