CVE detail
CVE-2015-9546 — CVE-2015-9546
Published 2020-04-10 · Modified 2026-06-17 · Vendor google · Product android · Source nvd
MEDIUM
severity
CVSS-derived band
0.0034
EPSS probability
exploitation probability, 30d
27.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences into an extracted file path. The Samsung ID is SVE-2015-4363 (November 2015).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References