CVE-2015-3864 PUBLISHED CVSS 10 CRITICAL

Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.

EPSS 87.03% · 99.4th percentile

Risk Scores

CVSS v2.0
10
EPSS Score
87.03%
99.4th percentile

Affected Products

VendorProductVersions
n/an/an/a
googleandroid0

Timeline

References

Open in Interactive Console →