CVE-2015-7893 describes a critical vulnerability in the SecEmailUI component of the Samsung Galaxy S6, where improper sanitization of HTML email content allows remote attackers to execute arbitrary JavaScript. This high-severity vulnerability, rated 8.8 CVSS, requires user interaction (UI:R) but can lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). While not in the KEV catalog, an ExploitDB entry (EDB-38554) confirms exploit code availability, and it has garnered significant community discussion and media coverage, including a SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:samsung:galaxy_s6:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.