CVE-2015-4496

Oracle Solaris < 37.0.2 - Numeric Error

Title source: rule
STIX 2.1

Description

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.

References (4)

Core 4
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1149605
Various Sources x_refsource_confirm
https://hg.mozilla.org/mozilla-central/rev/87277085561a

Scores

EPSS 0.0151
EPSS Percentile 81.5%

Details

CWE
CWE-189
Status published
Products (2)
mozilla/firefox < 37.0.2
oracle/solaris 11.3
Published Aug 16, 2015
Tracked Since Feb 18, 2026