10
CVSSv2

CVE-2015-3836

Published: 01/10/2015 Updated: 01/10/2015
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Parse_wave function in arm-wt-22k/lib_src/eas_mdls.c in the Sonivox DLS-to-EAS converter in Android prior to 5.1.1 LMY48I does not reject a negative value for a certain size field, which allows remote malicious users to execute arbitrary code or cause a denial of service (buffer overflow) via crafted XMF data, aka internal bug 21132860.

Vulnerable Product Search on Vulmon Subscribe to Product

google android