CVE-2015-4493 is a critical heap-based buffer overflow vulnerability in the libstagefright component of Mozilla Firefox before version 40.0 and Firefox ESR 38.x before 38.2, affecting products from vendors like Canonical, Mozilla, OpenSUSE, and Oracle. This flaw, related to CVE-2015-1539, allows remote attackers to execute arbitrary code by exploiting an invalid size field in MPEG-4 video data. With a CVSS score of 9.3, it represents a severe risk due to its network attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code is available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, it garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* | ||
<= 39.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
38.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:* | ||
38.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:* | ||
38.0.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.