CVE-2015-1538
Android <5.1.1 - RCE
Title source: llmDescription
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.
Exploits (8)
nomisec
WRITEUP
1 stars
by Tharana · poc
https://github.com/Tharana/Android-vulnerability-exploitation
nomisec
WORKING POC
1 stars
by renjithsasidharan · poc
https://github.com/renjithsasidharan/cve-2015-1538-1
nomisec
WORKING POC
by niranjanshr13 · poc
https://github.com/niranjanshr13/Stagefright-cve-2015-1538-1
exploitdb
WORKING POC
VERIFIED
by Joshua J. Drake · pythonremoteandroid
https://www.exploit-db.com/exploits/38124
References (8)
Scores
EPSS
0.8640
EPSS Percentile
99.4%
Classification
CWE
CWE-189
Status
draft
Affected Products (1)
google/android
< 5.1
Timeline
Published
Oct 01, 2015
Tracked Since
Feb 18, 2026