Kaios
Kaiostech · 10 CVEs
An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that r…
May 22, 2023
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.local…
May 22, 2023
An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns…
May 1, 2023
An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection…
Sep 14, 2020
An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injec…
Sep 14, 2020
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and Jav…
Sep 14, 2020
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and Ja…
Sep 14, 2020
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaSc…
Sep 14, 2020
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and…
Sep 14, 2020
A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 881…
Mar 17, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-33294 | An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port… | CRITICAL | 0.93% | May 22, 2023 |
| CVE-2023-33293 | An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed… | MEDIUM | 0.56% | May 22, 2023 |
| CVE-2023-27108 | An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns the user's call log without origin or pe… | MEDIUM | 0.57% | May 1, 2023 |
| CVE-2019-14761 | An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject ar… | MEDIUM | 0.40% | Sep 14, 2020 |
| CVE-2019-14760 | An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can injec… | MEDIUM | 0.40% | Sep 14, 2020 |
| CVE-2019-14759 | An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attac… | MEDIUM | 0.38% | Sep 14, 2020 |
| CVE-2019-14758 | An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker… | MEDIUM | 0.83% | Sep 14, 2020 |
| CVE-2019-14757 | An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can… | MEDIUM | 0.83% | Sep 14, 2020 |
| CVE-2019-14756 | An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacke… | MEDIUM | 0.80% | Sep 14, 2020 |
| CVE-2019-7386 | A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is… | MEDIUM | 3.71% | Mar 17, 2019 |
Showing 1 to 10 of 10 CVEs