CVE-2015-3864
HIGH 10.0EPSS 87.1%
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 87.12% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2015-10-01
- Updated
- 2024-08-06
Proof-of-concept exploits (6)
- Bhathiya404/Exploiting-Stagefright-Vulnerability-CVE-2015-38640★ · 2023-02-09
- Cmadhushanka/CVE-2015-3864-Exploitation0★ · 2024-07-10
- HenryVHuang/CVE-2015-38640★ · 2016-03-30
- HighW4y2H3ll/libstagefrightExploit2★ · 2016-04-22
- eudemonics/scaredycat17★ · 2015-12-08
- pwnaccelerator/stagefright-cve-2015-38643★ · 2015-08-18
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/40436
- https://www.exploit-db.com/exploits/38226
- https://www.exploit-db.com/exploits/39640