CVE-2018-10498
This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of file:/// URIs. The issue lies in the lack of proper validation of user-supplied data, which can allow for reading arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges. Was ZDI-CAN-5329.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.06%
- CWE
- CWE-37
- Published
- 2018-09-24
- Last modified
- 2026-03-14
Affected products
- Samsung Samsung Email
Weakness type
Related vulnerabilities
- CVE-2024-12806 — A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote...
- CVE-2023-20087 — Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
- CVE-2023-20077 — Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
- CVE-2022-20962 — A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could...
- CVE-2022-25347 — Delta Electronics DIAEnergie Path Traversal