Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64qw-gw3c-cgjv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

EPSS

Процентиль: 41%
0.00189
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
около 6 лет назад

The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

EPSS

Процентиль: 41%
0.00189
Низкий