CVE-2023-33293
- EPSS 0.16%
- Published 22.05.2023 16:15:10
- Last modified 21.11.2024 08:05:21
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to d...
CVE-2023-33294
- EPSS 0.32%
- Published 22.05.2023 16:15:10
- Last modified 21.11.2024 08:05:21
An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port 2929. The server accepts arbitrary Bash commands and executes them as root. Because it is ...
CVE-2023-27108
- EPSS 0.08%
- Published 01.05.2023 22:15:09
- Last modified 30.01.2025 17:15:13
An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns the user's call log without origin or permission checks. An attacker can inject a JavaScript payload that runs in a browser or app ...
CVE-2019-14757
- EPSS 0.24%
- Published 14.09.2020 20:15:10
- Last modified 21.11.2024 04:27:17
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assumi...
CVE-2019-14758
- EPSS 0.24%
- Published 14.09.2020 20:15:10
- Last modified 21.11.2024 04:27:17
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim that will inject HTML into the File Manager applica...
CVE-2019-14759
- EPSS 0.1%
- Published 14.09.2020 20:15:10
- Last modified 21.11.2024 04:27:17
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Radio application. At a bare minimum, this allows an...
CVE-2019-14760
- EPSS 0.1%
- Published 14.09.2020 20:15:10
- Last modified 21.11.2024 04:27:17
An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder application. At a bare minimum, this allows an attacker ...
CVE-2019-14761
- EPSS 0.1%
- Published 14.09.2020 20:15:10
- Last modified 21.11.2024 04:27:17
An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. At a bare minimum, this allows an attacker to take ...
CVE-2019-14756
- EPSS 0.24%
- Published 14.09.2020 19:15:10
- Last modified 21.11.2024 04:27:16
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email app...
CVE-2019-7386
- EPSS 2.66%
- Published 21.03.2019 16:01:12
- Last modified 21.11.2024 04:48:07
A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful e...