CVE-2015-1092
published 2015-04-10CVE-2015-1092: NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.37%
81.9th percentile
NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 8.2 | — |
| apple | tvos | <= 7.1 | — |
| apple | watch_os | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-1092: Watch OS 1.0.1
vendor_apple·CVSS 5.0
CVE-2015-1092 [MEDIUM] CVE-2015-1092: Watch OS 1.0.1
Apple Security Update: About the security content of Watch OS 1.0.1
Product: Watch OS
Version: 1.0.1
CVE: CVE-2015-1092
Component: CVE-ID
Apple
CVE-2015-1092: Apple TV 7.2
vendor_apple·CVSS 5.0
CVE-2015-1092 [MEDIUM] CVE-2015-1092: Apple TV 7.2
Apple Security Update: About the security content of Apple TV 7.2
Product: Apple TV
Version: 7.2
CVE: CVE-2015-1092
Component: CVE-ID
Apple
CVE-2015-1092: iOS 8.3
vendor_apple·CVSS 5.0
CVE-2015-1092 [MEDIUM] CVE-2015-1092: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1092
Component: CVE-ID
GHSA
GHSA-jpw3-r754-qmfw: NSXMLParser in Foundation in Apple iOS before 8
ghsa_unreviewed·2022-05-14
CVE-2015-1092 [MEDIUM] GHSA-jpw3-r754-qmfw: NSXMLParser in Foundation in Apple iOS before 8
NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00003.htmlhttp://www.securityfocus.com/bid/73983http://www.securitytracker.com/id/1032050https://support.apple.com/HT204661https://support.apple.com/HT204662https://support.apple.com/kb/HT204870http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Apr/msg00003.htmlhttp://www.securityfocus.com/bid/73983http://www.securitytracker.com/id/1032050https://support.apple.com/HT204661https://support.apple.com/HT204662https://support.apple.com/kb/HT204870
2015-04-10
Published