Lucene search

K
cve[email protected]CVE-2015-3876
HistoryOct 02, 2015 - 2:59 a.m.

CVE-2015-3876

2015-10-0202:59:02
CWE-20
web.nvd.nist.gov
38
cve-2015-3876
libstagefright
android
remote code execution
mp3
mp4
metadata
vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.064 Low

EPSS

Percentile

93.7%

libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.

Affected configurations

NVD
Node
googleandroidRange5.1.1
CPENameOperatorVersion
google:androidgoogle androidle5.1.1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.064 Low

EPSS

Percentile

93.7%