CVE-2015-4496
published 2015-08-16CVE-2015-4496: Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.02%
89.4th percentile
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 5.1 | — | |
| mozilla | firefox | <= 37.0.2 | — |
| mozilla | firefox | >= 0 < 40.0+build4-0ubuntu0.14.04.4 | 40.0+build4-0ubuntu0.14.04.4 |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Integer overflows in libstagefright while processing MP4 video metadata (MFSA 2015-93)
vendor_redhat·2015-08-12·CVSS 10.0
CVE-2015-4496 [CRITICAL] CWE-190 Mozilla: Integer overflows in libstagefright while processing MP4 video metadata (MFSA 2015-93)
Mozilla: Integer overflows in libstagefright while processing MP4 video metadata (MFSA 2015-93)
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
GHSA
GHSA-grmx-f2j7-2qwf: Multiple integer overflows in libstagefright in Mozilla Firefox before 38
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2015-4496 [CRITICAL] GHSA-grmx-f2j7-2qwf: Multiple integer overflows in libstagefright in Mozilla Firefox before 38
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
GHSA
GHSA-9662-qxrh-f9g6: Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2015-1538 [CRITICAL] GHSA-9662-qxrh-f9g6: Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.
OSV
CVE-2015-4496: Multiple integer overflows in libstagefright in Mozilla Firefox before 38
osv·2015-08-16·CVSS 10.0
CVE-2015-4496 [CRITICAL] CVE-2015-4496: Multiple integer overflows in libstagefright in Mozilla Firefox before 38
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
No detection rules found.
No public exploits indexed.
http://www.mozilla.org/security/announce/2015/mfsa2015-93.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1149605https://hg.mozilla.org/mozilla-central/rev/87277085561ahttp://www.mozilla.org/security/announce/2015/mfsa2015-93.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1149605https://hg.mozilla.org/mozilla-central/rev/87277085561a
2015-08-16
Published