Vulnerabilities > Bose > Soundtouch

DATE CVE VULNERABILITY TITLE RISK
2019-03-21 CVE-2018-12638 Cross-site Scripting vulnerability in Bose Soundtouch 18.1.4
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS.
network
bose CWE-79
4.3
2018-03-24 CVE-2017-17751 Unspecified vulnerability in Bose Soundtouch
Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol.
network
low complexity
bose
8.8
2018-03-24 CVE-2017-17750 Cross-site Scripting vulnerability in Bose Soundtouch
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
network
low complexity
bose CWE-79
5.4
2018-03-24 CVE-2017-17749 Cross-site Scripting vulnerability in Bose Soundtouch
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
network
low complexity
bose CWE-79
5.4