CVE-2015-3861: Google Android
Medium severity, CVSS 5.0. EPSS: 0.8% chance of exploitation in the next 30 days.
Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allow remote attackers to cause a denial of service (device inoperability) via crafted Matroska data, aka internal bug 21296336.
Affected products
- Google Android: up to and including 5.1
Published 2015-10-01. Last modified 2026-06-17.