VYPR

Vendor CVEs

LG

All CVEs

139 total · sorted by risk
  • CVE-2024-6178MedJun 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

  • CVE-2024-6177MedJun 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.

  • CVE-2024-2863MedMar 25, 2024
    risk 0.40cvss 5.3epss 0.64

    This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

  • CVE-2023-44124MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app launches implicit intents…

  • CVE-2023-44122MedSep 27, 2023
    risk 0.40cvss 6.1epss 0.00

    The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents…

  • CVE-2022-23728MedJan 21, 2022
    risk 0.40cvss 6.1epss 0.00

    Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.

  • CVE-2016-10398MedJul 17, 2017
    risk 0.40cvss 6.2epss 0.00

    Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay previously captured…

  • CVE-2021-30161MedApr 6, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection mechanism after an incoming call has been terminated. The LG ID is LVE-SMP-210002 (April 2021).

  • CVE-2021-3022MedJan 5, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 10 software. There was no write protection for the MTK protect2 partition. The LG ID is LVE-SMP-200028 (January 2021).

  • CVE-2020-7807MedSep 14, 2020
    risk 0.36cvss 5.6epss 0.00

    A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT____ of LG Electronics…

  • CVE-2020-13843MedJun 5, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June 2020).

  • CVE-2019-20784MedApr 17, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipsets) software. Interaction of GPS with 911 emergency calls is mishandled. The LG ID is LVE-SMP-180012 (January 2019).

  • CVE-2019-20779MedApr 17, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A TrustZone trusted application can crash via crafted input. The LG ID is LVE-SMP-190003 (May 2019).

  • CVE-2019-20776MedApr 17, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. A TZ trusted application can crash via crafted input. The LG ID is LVE-SMP-190005 (July 2019).

  • CVE-2019-20775MedApr 17, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets) software. Weak encryption leads to local information disclosure. The LG ID is LVE-SMP-190010 (August 2019).

  • CVE-2019-20774MedApr 17, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A system service allows local retrieval of the user's password. The LG ID is LVE-SMP-190009 (August 2019).

  • CVE-2016-10135MedJan 13, 2017
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5.0, and BLU R1 HD devices. The MTKLogger app with a package name of com.mediatek.mtklogger has application components that are…

  • CVE-2023-41181MedMay 3, 2024
    risk 0.35cvss 5.3epss 0.02

    LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit…

  • CVE-2023-44128MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.00

    he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the…

  • CVE-2023-44121MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.00

    The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action…

  • CVE-2018-10229MedMay 4, 2018
    risk 0.31cvss 4.8epss 0.01

    A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.

  • CVE-2020-9759MedMar 23, 2020
    risk 0.30cvss 4.6epss 0.00

    A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable…

  • CVE-2019-2191MedSep 27, 2019
    risk 0.28cvss 4.3epss 0.00

    In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required for exploitation.Product:…

  • CVE-2019-2190MedSep 27, 2019
    risk 0.28cvss 4.3epss 0.00

    In LG's LAF component, there is a possible leak of information in a protected disk partition due to a missing bounds check. This could lead to local information disclosure via USB with User execution privileges needed. User interaction is not required for exploitation.Product:…

  • CVE-2023-44129LowSep 27, 2023
    risk 0.23cvss 3.6epss 0.00

    The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality by launching this activity…

  • CVE-2023-44127LowSep 27, 2023
    risk 0.23cvss 3.6epss 0.00

    he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact details and phone numbers.

  • CVE-2023-44126LowSep 27, 2023
    risk 0.23cvss 3.6epss 0.00

    The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states,…

  • CVE-2021-38591LowAug 12, 2021
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).

  • CVE-2024-1886LowFeb 26, 2024
    risk 0.20cvss 3.0epss 0.01

    This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

  • CVE-2014-8757Feb 17, 2015
    risk 0.00cvss epss 0.05

    LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.

  • CVE-2014-7252Dec 5, 2014
    risk 0.00cvss epss 0.00

    Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets…

  • CVE-2014-7243Dec 5, 2014
    risk 0.00cvss epss 0.01

    LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2014-6636Sep 22, 2014
    risk 0.00cvss epss 0.00

    The LG Telepresence (aka com.rsupport.rtc.lge) application 2.0.12 Build 63 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2014-5563Sep 9, 2014
    risk 0.00cvss epss 0.00

    The Show do Milhao 2014 (aka br.com.lgrmobile.sdm) application 1.4.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2013-3666May 29, 2013
    risk 0.00cvss epss 0.00

    The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB Debugging mode, using Android Debug Bridge (adb) to establish a USB connection, dialing 3845#*973#, modifying the WLAN Test Wi-Fi…

  • CVE-2007-5558Oct 18, 2007
    risk 0.00cvss epss 0.02

    Integer overflow in the LG Mobile handset allows remote attackers to cause a denial of service (reboot) via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known…

  • CVE-2007-0524Jan 26, 2007
    risk 0.00cvss epss 0.01

    The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.

  • CVE-2006-2488May 19, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS (WOS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) del_folder, (2) nick, or (3) action parameters to (a) notes/index.php, (4) curr parameter to (b) ipod/get_ipod.php, and in (c)…

  • CVE-2005-1132May 2, 2005
    risk 0.00cvss epss 0.02

    LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file.

Page 3 of 3