webOS
by LG
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23730 | Cri | 0.64 | 9.8 | 0.01 | Mar 11, 2022 | The public API error causes for the attacker to be able to bypass API access control. | ||
| CVE-2023-6319 | Cri | 0.60 | 9.1 | 0.06 | Apr 9, 2024 | A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make… | ||
| CVE-2023-6318 | Cri | 0.60 | 9.1 | 0.05 | Apr 9, 2024 | A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated… | ||
| CVE-2023-6320 | Cri | 0.59 | 9.1 | 0.04 | Apr 9, 2024 | A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to… | ||
| CVE-2022-23731 | Hig | 0.51 | 7.8 | 0.01 | Mar 11, 2022 | V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models. | ||
| CVE-2022-23727 | Hig | 0.51 | 7.8 | 0.00 | Jan 28, 2022 | There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege | ||
| CVE-2023-6317 | Hig | 0.47 | 7.2 | 0.01 | Apr 9, 2024 | A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA … | ||
| CVE-2024-1885 | Med | 0.41 | 6.3 | 0.01 | Feb 26, 2024 | This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage. | ||
| CVE-2020-9759 | Med | 0.30 | 4.6 | 0.00 | Mar 23, 2020 | A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable… | ||
| CVE-2024-1886 | Low | 0.20 | 3.0 | 0.01 | Feb 26, 2024 | This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage. | ||
| CVE-2006-2488 | 0.00 | — | 0.01 | May 19, 2006 | Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS (WOS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) del_folder, (2) nick, or (3) action parameters to (a) notes/index.php, (4) curr parameter to (b) ipod/get_ipod.php, and in (c)… |
- risk 0.64cvss 9.8epss 0.01
The public API error causes for the attacker to be able to bypass API access control.
- risk 0.60cvss 9.1epss 0.06
A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make…
- risk 0.60cvss 9.1epss 0.05
A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated…
- risk 0.59cvss 9.1epss 0.04
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to…
- risk 0.51cvss 7.8epss 0.01
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
- risk 0.51cvss 7.8epss 0.00
There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege
- risk 0.47cvss 7.2epss 0.01
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA …
- risk 0.41cvss 6.3epss 0.01
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
- risk 0.30cvss 4.6epss 0.00
A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable…
- risk 0.20cvss 3.0epss 0.01
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
- CVE-2006-2488May 19, 2006risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS (WOS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) del_folder, (2) nick, or (3) action parameters to (a) notes/index.php, (4) curr parameter to (b) ipod/get_ipod.php, and in (c)…