openatom CVE Vulnerabilities & Metrics

Focus on openatom vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About openatom Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with openatom. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total openatom CVEs: 89
Earliest CVE date: 09 Sep 2022, 15:15 UTC
Latest CVE date: 04 Mar 2025, 04:15 UTC

Latest CVE reference: CVE-2025-23420

Rolling Stats

30-day Count (Rolling): 11
365-day Count (Rolling): 49

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 58.06%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 58.06%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical openatom CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.0

Max CVSS: 0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 89
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS openatom CVEs

These are the five CVEs with the highest CVSS scores for openatom, sorted by severity first and recency.

All CVEs for openatom

CVE-2025-23420 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

CVE-2025-23418 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

CVE-2025-23414 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

CVE-2025-21084 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios.

CVE-2025-20081 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

CVE-2025-20042 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.

CVE-2025-20024 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only in restricted scenarios.

CVE-2025-20021 openatom vulnerability CVSS: 0 04 Mar 2025, 04:15 UTC

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

CVE-2025-0304 openatom vulnerability CVSS: 0 07 Feb 2025, 10:15 UTC

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

CVE-2025-0303 openatom vulnerability CVSS: 0 07 Feb 2025, 10:15 UTC

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.

CVE-2025-0302 openatom vulnerability CVSS: 0 07 Feb 2025, 10:15 UTC

in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.

CVE-2024-9978 openatom vulnerability CVSS: 0 03 Dec 2024, 13:15 UTC

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVE-2024-12082 openatom vulnerability CVSS: 0 03 Dec 2024, 13:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVE-2024-10074 openatom vulnerability CVSS: 0 03 Dec 2024, 13:15 UTC

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.

CVE-2024-47797 openatom vulnerability CVSS: 0 05 Nov 2024, 08:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

CVE-2024-47404 openatom vulnerability CVSS: 0 05 Nov 2024, 08:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

CVE-2024-47402 openatom vulnerability CVSS: 0 05 Nov 2024, 08:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.

CVE-2024-47137 openatom vulnerability CVSS: 0 05 Nov 2024, 08:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

CVE-2024-45382 openatom vulnerability CVSS: 0 08 Oct 2024, 04:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

CVE-2024-43697 openatom vulnerability CVSS: 0 08 Oct 2024, 04:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.

CVE-2024-43696 openatom vulnerability CVSS: 0 08 Oct 2024, 04:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

CVE-2024-39831 openatom vulnerability CVSS: 0 08 Oct 2024, 04:15 UTC

in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.

CVE-2024-39806 openatom vulnerability CVSS: 0 08 Oct 2024, 04:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVE-2024-41160 openatom vulnerability CVSS: 0 02 Sep 2024, 05:15 UTC

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

CVE-2024-39612 openatom vulnerability CVSS: 0 02 Sep 2024, 05:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVE-2024-38382 openatom vulnerability CVSS: 0 02 Sep 2024, 05:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVE-2024-37185 openatom vulnerability CVSS: 0 02 Jul 2024, 09:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

CVE-2024-37077 openatom vulnerability CVSS: 0 02 Jul 2024, 09:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

CVE-2024-37030 openatom vulnerability CVSS: 0 02 Jul 2024, 09:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

CVE-2024-36278 openatom vulnerability CVSS: 0 02 Jul 2024, 09:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

CVE-2024-36260 openatom vulnerability CVSS: 0 02 Jul 2024, 09:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

CVE-2024-36243 openatom vulnerability CVSS: 0 02 Jul 2024, 09:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

CVE-2024-31071 openatom vulnerability CVSS: 0 02 Jul 2024, 09:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

CVE-2024-3759 openatom vulnerability CVSS: 0 07 May 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

CVE-2024-3758 openatom vulnerability CVSS: 0 07 May 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.

CVE-2024-3757 openatom vulnerability CVSS: 0 07 May 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.

CVE-2024-31078 openatom vulnerability CVSS: 0 07 May 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference.

CVE-2024-27217 openatom vulnerability CVSS: 0 07 May 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

CVE-2024-23808 openatom vulnerability CVSS: 0 07 May 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.

CVE-2024-29086 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.

CVE-2024-29074 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.

CVE-2024-28951 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

CVE-2024-28226 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.

CVE-2024-24581 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.

CVE-2024-22180 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

CVE-2024-22177 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.

CVE-2024-22098 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

CVE-2024-22092 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.

CVE-2024-21834 openatom vulnerability CVSS: 0 02 Apr 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

CVE-2024-21826 openatom vulnerability CVSS: 0 04 Mar 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause sensitive information leak through insecure storage.

CVE-2024-21816 openatom vulnerability CVSS: 0 04 Mar 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through improper preservation of permissions.

CVE-2023-49602 openatom vulnerability CVSS: 0 04 Mar 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

CVE-2023-46708 openatom vulnerability CVSS: 0 04 Mar 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.

CVE-2023-25176 openatom vulnerability CVSS: 0 04 Mar 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVE-2024-21863 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

CVE-2024-21860 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

CVE-2024-21851 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

CVE-2024-21845 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

CVE-2024-0285 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

CVE-2023-49118 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

CVE-2023-45734 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

CVE-2023-43756 openatom vulnerability CVSS: 0 02 Feb 2024, 07:15 UTC

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

CVE-2023-49142 openatom vulnerability CVSS: 0 02 Jan 2024, 08:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.

CVE-2023-49135 openatom vulnerability CVSS: 0 02 Jan 2024, 08:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

CVE-2023-48360 openatom vulnerability CVSS: 0 02 Jan 2024, 08:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

CVE-2023-47857 openatom vulnerability CVSS: 0 02 Jan 2024, 08:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.

CVE-2023-47216 openatom vulnerability CVSS: 0 02 Jan 2024, 08:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources

CVE-2023-6045 openatom vulnerability CVSS: 0 20 Nov 2023, 12:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.

CVE-2023-47217 openatom vulnerability CVSS: 0 20 Nov 2023, 12:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.

CVE-2023-46705 openatom vulnerability CVSS: 0 20 Nov 2023, 12:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion.

CVE-2023-46100 openatom vulnerability CVSS: 0 20 Nov 2023, 12:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.

CVE-2023-43612 openatom vulnerability CVSS: 0 20 Nov 2023, 12:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.

CVE-2023-42774 openatom vulnerability CVSS: 0 20 Nov 2023, 12:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.

CVE-2023-3116 openatom vulnerability CVSS: 0 20 Nov 2023, 12:15 UTC

in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.

CVE-2023-4753 openatom vulnerability CVSS: 0 21 Sep 2023, 10:15 UTC

OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input.

CVE-2023-25947 openatom vulnerability CVSS: 0 10 Mar 2023, 11:15 UTC

The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious HAP package.

CVE-2023-24465 openatom vulnerability CVSS: 0 10 Mar 2023, 11:15 UTC

Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.

CVE-2023-22436 openatom vulnerability CVSS: 0 10 Mar 2023, 11:15 UTC

The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.

CVE-2023-22301 openatom vulnerability CVSS: 0 10 Mar 2023, 11:15 UTC

The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerability which network attackers can launch a remote attack to obtain kernel memory data of the target system.

CVE-2023-0083 openatom vulnerability CVSS: 0 10 Mar 2023, 11:15 UTC

The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to crash.

CVE-2023-0036 openatom vulnerability CVSS: 0 09 Jan 2023, 03:15 UTC

platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

CVE-2023-0035 openatom vulnerability CVSS: 0 09 Jan 2023, 03:15 UTC

softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

CVE-2022-45126 openatom vulnerability CVSS: 0 09 Jan 2023, 03:15 UTC

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

CVE-2022-43662 openatom vulnerability CVSS: 0 09 Jan 2023, 03:15 UTC

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

CVE-2022-44455 openatom vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

CVE-2022-41802 openatom vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space incorrectly and leaked.

CVE-2022-41686 openatom vulnerability CVSS: 0 14 Oct 2022, 15:16 UTC

OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.

CVE-2022-38701 openatom vulnerability CVSS: 0 09 Sep 2022, 15:15 UTC

OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.

CVE-2022-36423 openatom vulnerability CVSS: 0 09 Sep 2022, 15:15 UTC

OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.