CVE-2015-7894 describes a critical memory corruption vulnerability in the DCMProvider service within Samsung's LibQjpeg library, affecting Samsung Galaxy S6 Edge devices running specific firmware. A remote attacker can exploit this flaw by sending a crafted JPG image, leading to a denial of service through a segmentation fault and process crash, and potentially enabling arbitrary code execution. With a CVSS v3 score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, requiring user interaction. While not listed on the KEV catalog, public exploit code exists (EDB-38614), and it has garnered some community discussion and media coverage, though it is not currently considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
lrx22g.g925vvru1aoe2CPE matchmatch criteria | cpe:2.3:o:samsung:galaxy_s6_edge_firmware:lrx22g.g925vvru1aoe2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.