
CVE-2023-47857 – multimedia camera has a UAF vulnerability
https://notcve.org/view.php?id=CVE-2023-47857
02 Jan 2024 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque el bloqueo de la cámara multimedia modificando un puntero liberado. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-01.md • CWE-416: Use After Free •

CVE-2023-47216 – Liteos-A has a missing release of resource vulnerability
https://notcve.org/view.php?id=CVE-2023-47216
02 Jan 2024 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local haga que DOS ocupe todos los recursos • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-01.md • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2023-47217 – Arkruntime has a buffer overflow vulnerability
https://notcve.org/view.php?id=CVE-2023-47217
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque DOS a través de un desbordamiento del búfer. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2023-46100 – Cert manager has a use of uninitialized resource vulnerability
https://notcve.org/view.php?id=CVE-2023-46100
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local obtenga información confidencial del búfer mediante el uso de recursos no inicializados. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-908: Use of Uninitialized Resource •

CVE-2023-42774 – Liteos-A has a incorrect default permissions vulnerability
https://notcve.org/view.php?id=CVE-2023-42774
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local obtenga información confidencial a través de permisos predeterminados incorrectos. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-276: Incorrect Default Permissions •

CVE-2023-6045 – Arkruntime has a type confusion vulnerability
https://notcve.org/view.php?id=CVE-2023-6045
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local ejecute código arbitrario en aplicaciones preinstaladas mediante confusión de tipos. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2023-46705 – Arkruntime has a type confusion vulnerability
https://notcve.org/view.php?id=CVE-2023-46705
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local provoque una fuga de información del sistema a través de confusión de tipos. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2023-43612 – Hiview has an improper preservation of permissions vulnerability
https://notcve.org/view.php?id=CVE-2023-43612
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local lea y escriba archivos arbitrarios mediante la preservación inadecuada de los permisos. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-281: Improper Preservation of Permissions •

CVE-2023-3116 – Liteos-A has a incorrect default permissions vulnerability
https://notcve.org/view.php?id=CVE-2023-3116
20 Nov 2023 — in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions. En OpenHarmony v3.2.2 y versiones anteriores permiten que un atacante local obtenga información confidencial o reescriba archivos confidenciales mediante permisos predeterminados incorrectos. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md • CWE-276: Incorrect Default Permissions •

CVE-2023-4753 – OpenHarmony v3.2.1 and prior version has a system call function usage error
https://notcve.org/view.php?id=CVE-2023-4753
21 Sep 2023 — OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input. OpenHarmony v3.2.1 y versiones anteriores tienen un error de uso de la función de llamada al sistema. Los atacantes locales pueden bloquear el kernel debido a la entrada de error. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-11.md • CWE-20: Improper Input Validation •