← Back

Soundtouch

soundtouch

Vendor: Bose • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bose
1Soundtouch
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker...Show more
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker has been connected to the app.Show less
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol.
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.