Description
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7578 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios. |
References
History
Tue, 04 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Mar 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios. | |
| Title | Communication Dsoftbus has an UAF vulnerability | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OpenHarmony
Published:
Updated: 2025-03-04T14:28:22.984Z
Reserved: 2025-01-20T02:01:05.553Z
Link: CVE-2025-20091
Updated: 2025-03-04T14:28:18.692Z
Status : Received
Published: 2025-03-04T04:15:13.253
Modified: 2025-03-04T04:15:13.253
Link: CVE-2025-20091
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:23Z
Weaknesses
EUVD