Lg Electronics Lg V60 Thin Q 5G vulnerabilities

9 known vulnerabilities affecting lg_electronics/lg_v60_thin_q_5g.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3LOW3

Vulnerabilities

Page 1 of 1
CVE-2023-44123HIGHCVSS 7.8vAndroid 12, 132023-09-27
CVE-2023-44123 [HIGH] CWE-285 CVE-2023-44123: The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before mak
nvd
CVE-2023-44122HIGHCVSS 7.8vAndroid 12, 132023-09-27
CVE-2023-44122 [HIGH] CWE-927 CVE-2023-44122: The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("c The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device.
nvd
CVE-2023-44125HIGHCVSS 7.8vAndroid 12, 132023-09-27
CVE-2023-44125 [HIGH] CWE-285 CVE-2023-44125: The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before
nvd
CVE-2023-44126MEDIUMCVSS 5.5≥ Android 8, ≤ 132023-09-27
CVE-2023-44126 [MEDIUM] CWE-925 CVE-2023-44126: The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states, durations, called numbers, contacts info, etc.
nvd
CVE-2023-44127MEDIUMCVSS 5.5≥ Android 8, ≤ 132023-09-27
CVE-2023-44127 [MEDIUM] CWE-927 CVE-2023-44127: he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launch he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact details and phone numbers.
nvd
CVE-2023-44121MEDIUMCVSS 6.3≥ Android 9, ≤ 132023-09-27
CVE-2023-44121 [MEDIUM] CWE-926 CVE-2023-44121: The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/ The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action "com.lge.lms.things.notification.ACTION". Additionally, this vulnerabili
nvd
CVE-2023-44128LOWCVSS 3.6≥ Android 4, ≤ 132023-09-27
CVE-2023-44128 [LOW] CWE-367 CVE-2023-44128: he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete f
nvd
CVE-2023-44129LOWCVSS 3.3≥ Android 12, ≤ 132023-09-27
CVE-2023-44129 [LOW] CWE-926 CVE-2023-44129: The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-cont The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality by launching this activity and then sending a broadcast with the "com.lge.message.action.QCLIP" actio
nvd
CVE-2023-44124LOWCVSS 3.3vAndroid 12, 132023-09-27
CVE-2023-44124 [LOW] CWE-927 CVE-2023-44124: The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. T
nvd