// For flags

CVE-2015-4641

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.

Vulnerabilidad de salto de directorio en la implementación de la actualización del paquete de lenguas SwiftKey en los dispositivos Samsung Galaxy S4, S4 Mini, S5, y S6 permite servidores web remotos escribir en ficheros arbitrarios, y como consecuencia ejecutar código arbitrario en un contexto privilegiado, mediante el aprovechamiento del control del nombre de dominio skslm.swiftkey.net y la provisión de un .. (punto punto) en una entrada en un archivo ZIP, tal y como fue demostrado por un salto en el directorio /data/dalvik-cache.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-06-17 CVE Reserved
  • 2015-06-19 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S4
Search vendor "Samsung" for product "Galaxy S4"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S4 Mini
Search vendor "Samsung" for product "Galaxy S4 Mini"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S5
Search vendor "Samsung" for product "Galaxy S5"
*-
Safe
Swiftkey
Search vendor "Swiftkey"
Swiftkey Sdk
Search vendor "Swiftkey" for product "Swiftkey Sdk"
*-
Affected
in Samsung
Search vendor "Samsung"
Galaxy S6
Search vendor "Samsung" for product "Galaxy S6"
*-
Safe