{ "schema_version": "1.4.0", "id": "GHSA-wj24-m2m7-q8x2", "modified": "2022-05-13T01:22:49Z", "published": "2022-05-13T01:22:49Z", "aliases": [ "CVE-2019-7386" ], "details": "A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code execution on the device.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7386" }, { "type": "WEB", "url": "https://s3curityb3ast.github.io" }, { "type": "WEB", "url": "https://s3curityb3ast.github.io/KSA-Dev-007.md" }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/151651/Nokia-8810-Denial-Of-Service.html" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2019/Feb/35" }, { "type": "WEB", "url": "http://www.breakthesec.com" }, { "type": "WEB", "url": "http://www.breakthesec.com/search/label/0day" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-03-21T16:01:00Z" } }