← back
CVE-2015-3864

CVE-2015-3864

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 87%
from disclosure to weapon0 days
Published on NVDOct 1
1st PoCAug 18
metasploitAug 13
exploitation probability
87%top 1% of all CVEs
observed exploitation
nono source reports it
11 public exploit(s)
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.