← Vulnerability feed

Vulnerability record · CVE-2024-37077 · published 2 July 2024

CVE-2024-37077: Openatom openharmony out-of-bounds write vulnerability

Openatom · Openharmony

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

9.8 CVSS 3.1 Critical EPSS 0.62% · top 52.4% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37077 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-37185Openatom openharmony out-of-bounds write vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.EPSS 0.62%9.8CVE-2024-36243Openatom openharmony out-of-bounds read vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.EPSS 0.57%9.8CVE-2024-36260Openatom openharmony out-of-bounds write vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.EPSS 0.57%9.8CVE-2024-37030Openatom openharmony use after free vulnerabilityin OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.EPSS 0.57%8.8CVE-2025-22851Openatom openharmony integer overflow vulnerabilityin OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.EPSS 0.18%8.8CVE-2024-47398Openatom openharmony out-of-bounds write vulnerabilityin OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bounds write.EPSS 0.16%8.8CVE-2024-29074Openatom openharmony improper input validation vulnerabilityin OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.EPSS 0.18%8.8CVE-2024-22098Openatom openharmony use after free vulnerabilityin OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after free.EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2024-37077), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.