CVE-2015-1092
Apple iOS < 8.3 and Apple TV < 7.2 - XML External Entity Injection in NSXMLParser
Title source: llmDescription
NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References (7)
Core 7
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT204870
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/73983
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032050
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204662
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT204661
Scores
EPSS
0.0236
EPSS Percentile
82.0%
Details
Status
published
Products (2)
apple/iphone_os
< 8.2
apple/tvos
< 7.1
Published
Apr 10, 2015
Tracked Since
Feb 18, 2026