{"api_version":"1","generated_at":"2026-07-23T12:27:17+00:00","cve":"CVE-2015-1538","urls":{"html":"https://cve.report/CVE-2015-1538","api":"https://cve.report/api/cve/CVE-2015-1538.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1538","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1538"},"summary":{"title":"CVE-2015-1538","description":"Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-10-01 00:59:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/38124/","name":"https://www.exploit-db.com/exploits/38124/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Android Stagefright - Remote Code Execution - Exploits Database","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/76052","name":"http://www.securityfocus.com/bid/76052","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Stagefright Media Playback Engine Multiple Remote Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://android.googlesource.com/platform/frameworks/av/+/2434839bbd168469f80dd9a22f1328bc81046398","name":"https://android.googlesource.com/platform/frameworks/av/+/2434839bbd168469f80dd9a22f1328bc81046398","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"2434839bbd168469f80dd9a22f1328bc81046398 - platform/frameworks/av - Git at Google","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/134131/Libstagefright-Integer-Overflow-Check-Bypass.html","name":"http://packetstormsecurity.com/files/134131/Libstagefright-Integer-Overflow-Check-Bypass.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Libstagefright Integer Overflow Check Bypass ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm","name":"http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory - Stagefright Vulnerability in Multiple Huawei Android Products","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.huawei.com/en/psirt/security-advisories/hw-448928","name":"http://www.huawei.com/en/psirt/security-advisories/hw-448928","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory - Stagefright Vulnerability in Multiple Huawei Android Products","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1033094","name":"http://www.securitytracker.com/id/1033094","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Android MMS Media Processing Flaw Lets Remote Users Execute Arbitrary Code on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJ","name":"https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJ","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"500","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1538","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1538","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1538","vulnerable":"1","versionEndIncluding":"5.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:47:16.832Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://android.googlesource.com/platform/frameworks/av/+/2434839bbd168469f80dd9a22f1328bc81046398"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/134131/Libstagefright-Integer-Overflow-Check-Bypass.html"},{"name":"1033094","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033094"},{"name":"76052","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76052"},{"name":"38124","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/38124/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.huawei.com/en/psirt/security-advisories/hw-448928"},{"name":"[android-security-updates] 20150812 Nexus Security Bulletin (August 2015)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJ"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-08-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-20T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://android.googlesource.com/platform/frameworks/av/+/2434839bbd168469f80dd9a22f1328bc81046398"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/134131/Libstagefright-Integer-Overflow-Check-Bypass.html"},{"name":"1033094","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033094"},{"name":"76052","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76052"},{"name":"38124","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/38124/"},{"tags":["x_refsource_CONFIRM"],"url":"http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.huawei.com/en/psirt/security-advisories/hw-448928"},{"name":"[android-security-updates] 20150812 Nexus Security Bulletin (August 2015)","tags":["mailing-list","x_refsource_MLIST"],"url":"https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJ"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-1538","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://android.googlesource.com/platform/frameworks/av/+/2434839bbd168469f80dd9a22f1328bc81046398","refsource":"CONFIRM","url":"https://android.googlesource.com/platform/frameworks/av/+/2434839bbd168469f80dd9a22f1328bc81046398"},{"name":"http://packetstormsecurity.com/files/134131/Libstagefright-Integer-Overflow-Check-Bypass.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/134131/Libstagefright-Integer-Overflow-Check-Bypass.html"},{"name":"1033094","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033094"},{"name":"76052","refsource":"BID","url":"http://www.securityfocus.com/bid/76052"},{"name":"38124","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/38124/"},{"name":"http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm","refsource":"CONFIRM","url":"http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-448928.htm"},{"name":"http://www.huawei.com/en/psirt/security-advisories/hw-448928","refsource":"CONFIRM","url":"http://www.huawei.com/en/psirt/security-advisories/hw-448928"},{"name":"[android-security-updates] 20150812 Nexus Security Bulletin (August 2015)","refsource":"MLIST","url":"https://groups.google.com/forum/message/raw?msg=android-security-updates/Ugvu3fi6RQM/yzJvoTVrIQAJ"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-1538","datePublished":"2015-10-01T00:00:00.000Z","dateReserved":"2015-02-06T00:00:00.000Z","dateUpdated":"2024-08-06T04:47:16.832Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-10-01 00:59:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionEndIncluding":"5.1","matchCriteriaId":"3573E693-716C-4B92-AC87-6466CBC26527"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1538","Ordinal":"1","Title":"CVE-2015-1538","CVE":"CVE-2015-1538","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1538","Ordinal":"1","NoteData":"Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.","Type":"Description","Title":"CVE-2015-1538"},{"CveYear":"2015","CveId":"1538","Ordinal":"2","NoteData":"2015-09-30","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1538","Ordinal":"3","NoteData":"2017-09-20","Type":"Other","Title":"Modified"}]}}}