Unrated severityNVD Advisory· Published Oct 1, 2015· Updated Jun 17, 2026
CVE-2015-3864
CVE-2015-3864
Description
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <5.1.1 / LMY48M
Patches
Vulnerability mechanics
References
8- android.googlesource.com/platform/frameworks/av/+/6fe85f7e15203e48df2cc3e8e1c4bc6ad49dc968nvdVendor Advisory
- blog.zimperium.com/cve-2015-3864-metasploit-module-now-available-for-testing/nvdRelease NotesThird Party Advisory
- groups.google.com/forum/message/rawnvdVendor Advisory
- www.securityfocus.com/bid/76682nvd
- blog.zimperium.com/reflecting-on-stagefright-patches/nvd
- www.exploit-db.com/exploits/38226/nvd
- www.exploit-db.com/exploits/39640/nvd
- www.exploit-db.com/exploits/40436/nvd
News mentions
0No linked articles in our index yet.