cbcvebase.
CVE-2015-6602
published 2015-10-02

CVE-2015-6602: libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated…

PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.19%
86.6th percentile
libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianandroid-platform-frameworks-native
googleandroid<= 5.1.1
googleandroid

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.