CVE-2015-7893: Input Validation
Published Apr 11, 2017
·Updated
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
Affected Software
1 affected component
Samsung Galaxy S6
Event History
Apr 11, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7893?
CVE-2015-7893 has been assigned a medium severity rating due to its potential for remote code execution via JavaScript injection.
2
How do I fix CVE-2015-7893?
To fix CVE-2015-7893, ensure that your Samsung Galaxy S6 firmware is updated to the latest version provided by Samsung.
3
What type of attack does CVE-2015-7893 allow?
CVE-2015-7893 allows attackers to execute arbitrary JavaScript within the SecEmailUI component of the Samsung Galaxy S6.
4
Which devices are affected by CVE-2015-7893?
CVE-2015-7893 primarily affects the Samsung Galaxy S6 and may involve other versions with the same email client feature.
5
Is user interaction required for exploiting CVE-2015-7893?
Yes, CVE-2015-7893 typically requires user interaction, as the attacker must trick the user into opening a malicious email.