彙總 OpenAtom Foundation 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
已披露問題常與 記憶體損壞、緩衝區溢位與輸入驗證問題 相關,可能在 軟體部署與生產負載 場景中帶來 應用程式崩潰與記憶體損壞 等暴露風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2026-0639 | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. | [email protected] | 3.3 | 0.01% | 2026-03-16 | 2026-03-17 |
| CVE-2025-6969 | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. | [email protected] | 5.0 | 0.02% | 2026-03-16 | 2026-03-17 |
| CVE-2025-52458 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | [email protected] | 5.5 | 0.01% | 2026-03-16 | 2026-03-17 |
| CVE-2025-41432 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | [email protected] | 5.5 | 0.01% | 2026-03-16 | 2026-03-17 |
| CVE-2025-26474 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios. | [email protected] | 3.3 | 0.02% | 2026-03-16 | 2026-03-17 |
| CVE-2025-25277 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios. | [email protected] | 6.3 | 0.01% | 2026-03-16 | 2026-03-17 |
| CVE-2025-12736 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource. | [email protected] | 6.5 | 0.01% | 2026-03-16 | 2026-03-17 |
| CVE-2025-27577 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | [email protected] | 8.4 | 0.01% | 2025-08-11 | 2025-08-12 |
| CVE-2025-27562 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. | [email protected] | 3.3 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-27536 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion. | [email protected] | 3.3 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-27128 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | [email protected] | 8.4 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-26690 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. | [email protected] | 3.3 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-25278 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | [email protected] | 8.4 | 0.01% | 2025-08-11 | 2025-08-12 |
| CVE-2025-25212 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input. | [email protected] | 3.3 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-24925 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. | [email protected] | 3.3 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-24844 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. | [email protected] | 3.3 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-24298 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | [email protected] | 8.4 | 0.07% | 2025-08-11 | 2025-08-12 |
| CVE-2025-27563 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. | [email protected] | 3.3 | 0.06% | 2025-06-08 | 2025-06-09 |
| CVE-2025-27247 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. | [email protected] | 5.5 | 0.06% | 2025-06-08 | 2025-06-09 |
| CVE-2025-27242 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input. | [email protected] | 3.3 | 0.07% | 2025-06-08 | 2025-06-09 |