{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-07T16:21:20.623","vulnerabilities":[{"cve":{"id":"CVE-2022-44455","sourceIdentifier":"scy@openharmony.io","published":"2022-12-08T16:15:13.413","lastModified":"2024-11-21T07:28:02.960","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application would be able to gain code execution within any application installed on the device or cause application crash."},{"lang":"es","value":"Se descubrió que los servicios appspawn y nwebspawn dentro de OpenHarmony-v3.1.2 y versiones anteriores eran vulnerables a la vulnerabilidad de desbordamiento de búfer debido a una validación de entrada insuficiente. Una aplicación maliciosa sin privilegios podría obtener la ejecución de código dentro de cualquier aplicación instalada en el dispositivo o provocar el bloqueo de la aplicación."}],"metrics":{"cvssMetricV31":[{"source":"scy@openharmony.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.5,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"scy@openharmony.io","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndIncluding":"3.1.2","matchCriteriaId":"C026D184-A8AE-4DE6-A339-EA4469DDD4E7"},{"vulnerable":true,"criteria":"cpe:2.3:o:openatom:openharmony:*:*:*:*:lts:*:*:*","versionStartIncluding":"3.0","versionEndIncluding":"3.0.6","matchCriteriaId":"DD78C0F7-A817-473C-88B3-E7BC1A640AB5"}]}]}],"references":[{"url":"https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-12.md","source":"scy@openharmony.io","tags":["Third Party Advisory"]},{"url":"https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-12.md","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}