CVE-2015-1538

Android <5.1.1 - RCE

Title source: llm

Description

Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.

Exploits (8)

nomisec WORKING POC 205 stars
by jduck · poc
https://github.com/jduck/cve-2015-1538-1
nomisec WORKING POC 3 stars
by oguzhantopgul · poc
https://github.com/oguzhantopgul/cve-2015-1538-1
nomisec WRITEUP 2 stars
by Tharana · poc
https://github.com/Tharana/vulnerability-exploitation
nomisec WRITEUP 1 stars
by Tharana · poc
https://github.com/Tharana/Android-vulnerability-exploitation
nomisec WORKING POC 1 stars
by renjithsasidharan · poc
https://github.com/renjithsasidharan/cve-2015-1538-1
nomisec WORKING POC
by niranjanshr13 · poc
https://github.com/niranjanshr13/Stagefright-cve-2015-1538-1
nomisec STUB
by xsleaksiki · poc
https://github.com/xsleaksiki/cve
exploitdb WORKING POC VERIFIED
by Joshua J. Drake · pythonremoteandroid
https://www.exploit-db.com/exploits/38124

Scores

EPSS 0.8640
EPSS Percentile 99.4%

Classification

CWE
CWE-189
Status draft

Affected Products (1)

google/android < 5.1

Timeline

Published Oct 01, 2015
Tracked Since Feb 18, 2026