CVE-2015-3784
published 2015-08-16CVE-2015-3784: Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.50%
82.9th percentile
Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 8.4 | — |
| apple | iwork | <= 2.5.4 | — |
| apple | keynote | <= 6.5 | — |
| apple | keynote_6.6_pages_5.6_numbers_3.6_and_iwork_for_ios | — | — |
| apple | mac_os_x | <= 10.10.4 | — |
| apple | numbers | <= 3.5 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| apple | pages | <= 5.5.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-3784: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 5.0
CVE-2015-3784 [MEDIUM] CVE-2015-3784: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2015-3784
Component: CVE-ID
Apple
CVE-2015-3784: Apple TV 7.2.1
vendor_apple·CVSS 5.0
CVE-2015-3784 [MEDIUM] CVE-2015-3784: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3784
Component: CVE-ID
Apple
CVE-2015-3784: Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS 2.6
vendor_apple·CVSS 5.0
CVE-2015-3784 [MEDIUM] CVE-2015-3784: Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS 2.6
Apple Security Update: About the security content of Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS 2.6
Product: Keynote 6.6, Pages 5.6, Numbers 3.6, and iWork for iOS
Version: 2.6
CVE: CVE-2015-3784
Component: CVE-ID
Impact: Opening a maliciously crafted document may lead to unexpected application termination or arbitrary code execution
Description: A memory corruption issue existed in parsing a maliciously crafted document. This issue was addressed through improved memory handling.
Apple
CVE-2015-3784: iOS 8.4.1
vendor_apple·CVSS 5.0
CVE-2015-3784 [MEDIUM] CVE-2015-3784: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3784
Component: CVE-ID
GHSA
GHSA-ghj5-59w9-356m: Office Viewer in Apple iOS before 8
ghsa_unreviewed·2022-05-17
CVE-2015-3784 [MEDIUM] CWE-200 GHSA-ghj5-59w9-356m: Office Viewer in Apple iOS before 8
Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Oct/msg00000.htmlhttp://www.securityfocus.com/bid/76343http://www.securitytracker.com/id/1033275https://support.apple.com/HT205373https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Oct/msg00000.htmlhttp://www.securityfocus.com/bid/76343http://www.securitytracker.com/id/1033275https://support.apple.com/HT205373https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205031
2015-08-16
Published