Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefox | Dec 1, 2016 | Aug 15, 2015 |
| Freebsd | — | Upgrade libxulUpgrade linux-firefoxUpgrade firefoxUpgrade seamonkeyUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade firefox-esrUpgrade linux-thunderbird | Dec 10, 2025 | May 12, 2015 |
| Mfsa2015 93 | — | Upgrade to Mozilla Firefox version 38.0 | Aug 17, 2015 | Aug 15, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.35.0 | Oct 22, 2015 | Aug 15, 2015 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Aug 15, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 19, 2024 | Aug 16, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub