CVE-2023-0083

The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to crash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openharmony:openharmony:*:*:*:*:lts:*:*:*
cpe:2.3:a:openharmony:openharmony:*:*:*:*:-:*:*:*

History

07 Nov 2023, 03:59

Type Values Removed Values Added
Summary The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to crash. The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to crash.

14 Mar 2023, 18:01

Type Values Removed Values Added
CWE CWE-843
First Time Openharmony
Openharmony openharmony
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:openharmony:openharmony:*:*:*:*:lts:*:*:*
cpe:2.3:a:openharmony:openharmony:*:*:*:*:-:*:*:*
References (MISC) https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2023/2023-02.md - (MISC) https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2023/2023-02.md - Third Party Advisory

10 Mar 2023, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-10 11:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-0083

Mitre link : CVE-2023-0083

CVE.ORG link : CVE-2023-0083


JSON object : View

Products Affected

openharmony

  • openharmony
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')