Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown
CVE-2023-6320
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability.
Full versions and TV models affected:
* webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
* webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
0
Attacker Value
Unknown
CVE-2023-6319
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.
* webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA
* webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
* webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
* webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA
0
Attacker Value
Unknown
CVE-2023-6318
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.
Full versions and TV models affected:
* webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
* webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
* webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA
0
Attacker Value
Unknown
CVE-2023-6317
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.
Full versions and TV models affected:
webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA
webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA
0
Attacker Value
Unknown
CVE-2022-23731
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
0
Attacker Value
Unknown
CVE-2022-23730
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
The public API error causes for the attacker to be able to bypass API access control.
0
Attacker Value
Unknown
CVE-2022-23727
Disclosure Date: January 28, 2022 (last updated October 07, 2023)
There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege
0
Attacker Value
Unknown
CVE-2020-9759
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files.
0
Attacker Value
Unknown
CVE-2009-5098
Disclosure Date: September 13, 2011 (last updated October 04, 2023)
The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception.
0
Attacker Value
Unknown
CVE-2009-5097
Disclosure Date: September 13, 2011 (last updated October 04, 2023)
Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.
0