10
CVSSv2

CVE-2015-3832

Published: 01/10/2015 Updated: 01/10/2015
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android prior to 5.1.1 LMY48I allow remote malicious users to execute arbitrary code via invalid size values of NAL units in MP4 data, aka internal bug 19641538.

Vulnerable Product Search on Vulmon Subscribe to Product

google android

Github Repositories

Media Fuzzing Framework for Android

MFFA - Media Fuzzing Framework for Android (Stagefright fuzzer) Project overview The main idea behind this project is to create corrupt but structurally valid media files, direct them to the appropriate software components in Android to be decoded and/or played and monitor the system for potential issues (ie system crashes) that may lead to exploitable vulnerab