CVE-2015-3829 is an off-by-one error in the libstagefright component of Android before version 5.1.1 LMY48I. This critical vulnerability, with a CVSS score of 10.0, allows remote attackers to execute arbitrary code or cause a denial of service through crafted MPEG-4 files. While there are no public exploits like Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness. Despite its age, its high FAUCET Risk Score of 97/100 suggests continued relevance for risk assessment.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.