cbcvebase.
CVE-2015-4496
published 2015-08-16

CVE-2015-4496: Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an…

PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.02%
89.4th percentile
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.

Affected

4 ranges
VendorProductVersion rangeFixed in
googleandroid<= 5.1
mozillafirefox<= 37.0.2
mozillafirefox>= 0 < 40.0+build4-0ubuntu0.14.04.440.0+build4-0ubuntu0.14.04.4
oraclesolaris

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.