CVE-2015-7896 describes a denial-of-service vulnerability in LibQJpeg on Samsung Galaxy S6 devices prior to the October 2015 MR. An attacker can trigger memory corruption and a SIGSEGV crash by providing a specially crafted image file, requiring user interaction to open the malicious image. This vulnerability has a CVSS score of 6.5 (Medium), indicating a high impact on availability with low attack complexity. While not actively exploited in the wild, a proof-of-concept exploit exists on ExploitDB, and it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:samsung:samsung_mobile:5.0:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:o:samsung:samsung_mobile:5.0.1:*:*:*:*:*:*:* | ||
5.0.2CPE matchmatch criteria | cpe:2.3:o:samsung:samsung_mobile:5.0.2:*:*:*:*:*:*:* | ||
5.1CPE matchmatch criteria | cpe:2.3:o:samsung:samsung_mobile:5.1:*:*:*:*:*:*:* | ||
5.1.1CPE matchmatch criteria | cpe:2.3:o:samsung:samsung_mobile:5.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.