cbcvebase.
CVE-2015-3876
published 2015-10-02

CVE-2015-3876: libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.

PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.14%
86.4th percentile
libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.

Affected

2 ranges
VendorProductVersion rangeFixed in
googleandroid<= 5.1.1
googleandroid
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.