VYPR

webOS

by LG

CVEs (11)

  • CVE-2022-23730CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The public API error causes for the attacker to be able to bypass API access control.

  • CVE-2023-6319CriApr 9, 2024
    risk 0.60cvss 9.1epss 0.06

    A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make…

  • CVE-2023-6318CriApr 9, 2024
    risk 0.60cvss 9.1epss 0.05

    A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated…

  • CVE-2023-6320CriApr 9, 2024
    risk 0.59cvss 9.1epss 0.04

    A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to…

  • CVE-2022-23731HigMar 11, 2022
    risk 0.51cvss 7.8epss 0.01

    V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.

  • CVE-2022-23727HigJan 28, 2022
    risk 0.51cvss 7.8epss 0.00

    There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege

  • CVE-2023-6317HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.  Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA …

  • CVE-2024-1885MedFeb 26, 2024
    risk 0.41cvss 6.3epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

  • CVE-2020-9759MedMar 23, 2020
    risk 0.30cvss 4.6epss 0.00

    A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable…

  • CVE-2024-1886LowFeb 26, 2024
    risk 0.20cvss 3.0epss 0.01

    This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

  • CVE-2006-2488May 19, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS (WOS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) del_folder, (2) nick, or (3) action parameters to (a) notes/index.php, (4) curr parameter to (b) ipod/get_ipod.php, and in (c)…