CVE-2023-44127
- EPSS 0.05%
- Veröffentlicht 27.09.2023 15:19:37
- Zuletzt bearbeitet 21.11.2024 08:25:18
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact deta...
CVE-2023-44128
- EPSS 0.02%
- Veröffentlicht 27.09.2023 15:19:37
- Zuletzt bearbeitet 21.11.2024 08:25:18
he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are ...
CVE-2023-44129
- EPSS 0.03%
- Veröffentlicht 27.09.2023 15:19:37
- Zuletzt bearbeitet 21.11.2024 08:25:18
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionali...
CVE-2023-44126
- EPSS 0.05%
- Veröffentlicht 27.09.2023 15:19:36
- Zuletzt bearbeitet 21.11.2024 08:25:17
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data s...
CVE-2023-44121
- EPSS 0.03%
- Veröffentlicht 27.09.2023 15:19:35
- Zuletzt bearbeitet 21.11.2024 08:25:17
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending...
CVE-2023-44122
- EPSS 0.02%
- Veröffentlicht 27.09.2023 15:19:35
- Zuletzt bearbeitet 21.11.2024 08:25:17
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the a...
CVE-2023-44123
- EPSS 0.02%
- Veröffentlicht 27.09.2023 15:19:35
- Zuletzt bearbeitet 21.11.2024 08:25:17
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if...
CVE-2023-44124
- EPSS 0.02%
- Veröffentlicht 27.09.2023 15:19:35
- Zuletzt bearbeitet 21.11.2024 08:25:17
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the a...
CVE-2023-44125
- EPSS 0.02%
- Veröffentlicht 27.09.2023 15:19:35
- Zuletzt bearbeitet 21.11.2024 08:25:17
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app...
CVE-2023-35670
- EPSS 0.02%
- Veröffentlicht 11.09.2023 21:15:42
- Zuletzt bearbeitet 02.05.2025 17:15:47
In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges ne...