Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-44455

Опубликовано: 08 дек. 2022
Источник: nvd
CVSS3: 6.8
CVSS3: 7.8
EPSS Низкий

Описание

The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*:*
Версия от 3.1 (включая) до 3.1.2 (включая)
cpe:2.3:o:openatom:openharmony:*:*:*:*:lts:*:*:*
Версия от 3.0 (включая) до 3.0.6 (включая)

EPSS

Процентиль: 20%
0.00063
Низкий

6.8 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-120
CWE-120

Связанные уязвимости

CVSS3: 7.8
github
около 3 лет назад

The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash.

EPSS

Процентиль: 20%
0.00063
Низкий

6.8 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-120
CWE-120