CVE-2015-1092

Apple iOS < 8.3 and Apple TV < 7.2 - XML External Entity Injection in NSXMLParser

Title source: llm
STIX 2.1

Description

NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

References (7)

Core 7
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT204870
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73983
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032050
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204662
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204661

Scores

EPSS 0.0236
EPSS Percentile 82.0%

Details

Status published
Products (2)
apple/iphone_os < 8.2
apple/tvos < 7.1
Published Apr 10, 2015
Tracked Since Feb 18, 2026