CVE-2015-7888
Last modified
CVE-2015-7888 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download.. EPSS estimates a 4.05% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Galaxy S6 Edge Firmware | g925vvru1aoe2 |
References
- http://www.securityfocus.com/bid/77338Third Party Advisory, VDB Entry
- https://bugs.chromium.org/p/project-zero/issues/detail?id=489&q=samsung&redir=1Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/77338Third Party Advisory, VDB Entry
- https://bugs.chromium.org/p/project-zero/issues/detail?id=489&q=samsung&redir=1Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-7888?
How severe is CVE-2015-7888?
How do I fix CVE-2015-7888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-7881The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allow…
- CVE-2015-7882Improper handling of LDAP authentication in MongoDB Server v…8.1
- CVE-2015-7884The vivid_fb_ioctl function in drivers/media/platform/vivid/…
- CVE-2015-7885The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mg…
- CVE-2015-7886NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP acces…
- CVE-2015-7887NetApp SnapCenter Server 1.0 allows remote authenticated use…
- CVE-2015-7889The SecEmailComposer/EmailComposer application in the Samsun…
- CVE-2015-7890Multiple buffer overflows in the esa_write function in /dev/…5.5
- CVE-2015-7891Race condition in the ioctl implementation in the Samsung Gr…
- CVE-2015-7892Stack-based buffer overflow in the m2m1shot_compat_ioctl32 f…7.8
- CVE-2015-7893SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email…
- CVE-2015-7894The DCMProvider service in Samsung LibQjpeg on a Samsung SM-…
Are you affected by CVE-2015-7888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
