Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.
2015-08-16T01:59:07.817
2025-04-12T10:46:40.837
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | canonical | ubuntu_linux | 12.04 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 15.04 | Yes |
| Operating System | opensuse | opensuse | 13.1 | Yes |
| Operating System | opensuse | opensuse | 13.2 | Yes |
| Application | mozilla | firefox | ≤ 39.0.3 | Yes |
| Application | mozilla | firefox | 38.0 | Yes |
| Application | mozilla | firefox | 38.0.1 | Yes |
| Application | mozilla | firefox | 38.0.5 | Yes |
| Application | mozilla | firefox | 38.1.0 | Yes |