Medium severity4.8NVD Advisory· Published Apr 10, 2020· Updated Jun 17, 2026
CVE-2015-9546
CVE-2015-9546
Description
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences into an extracted file path. The Samsung ID is SVE-2015-4363 (November 2015).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Samsung/mobile devicesdescription
- Range: <=2015-06-16
Patches
Vulnerability mechanics
References
1- security.samsungmobile.com/securityUpdate.smsbnvdVendor Advisory
News mentions
0No linked articles in our index yet.