CVE-2015-3807
published 2015-08-17CVE-2015-3807: libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.41%
82.4th percentile
libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | — | — |
| apple | ios | — | — |
| apple | iphone_os | <= 8.4 | — |
| apple | iphone_os | <= 9.1 | — |
| apple | mac_os_x | <= 10.10.4 | — |
| apple | mac_os_x | <= 10.11.1 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| apple | tvos | <= 9.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5qg-57g2-2cqg: libxml2 in Apple iOS before 8
ghsa_unreviewed·2022-05-14
CVE-2015-3807 [MEDIUM] CWE-119 GHSA-f5qg-57g2-2cqg: libxml2 in Apple iOS before 8
libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.
Apple
CVE-2015-3807: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 4.3
CVE-2015-3807 [MEDIUM] CVE-2015-3807: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2015-3807
Component: CVE-ID
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue existed in handling of malformed XPC messages. This issue was improved through improved bounds checking.
Apple
CVE-2015-3807: Apple TV 7.2.1
vendor_apple·CVSS 4.3
CVE-2015-3807 [MEDIUM] CVE-2015-3807: Apple TV 7.2.1
Apple Security Update: About the security content of Apple TV 7.2.1
Product: Apple TV
Version: 7.2.1
CVE: CVE-2015-3807
Component: CVE-ID
Impact: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2, the most serious of which may allow a remote attacker to cause a denial of service
Description: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2. These were addressed by updating libxml2 to version 2.9.2.
Apple
CVE-2015-3807: iOS 8.4.1
vendor_apple·CVSS 4.3
CVE-2015-3807 [MEDIUM] CVE-2015-3807: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3807
Component: CVE-ID
Impact: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2, the most serious of which may allow a remote attacker to cause a denial of service
Description: Multiple vulnerabilities existed in libxml2 versions prior to 2.9.2. These were addressed by updating libxml2 to version 2.9.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://www.securityfocus.com/bid/76343http://www.securitytracker.com/id/1033275https://support.apple.com/HT205635https://support.apple.com/HT205637https://support.apple.com/HT205640https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://www.securityfocus.com/bid/76343http://www.securitytracker.com/id/1033275https://support.apple.com/HT205635https://support.apple.com/HT205637https://support.apple.com/HT205640https://support.apple.com/kb/HT205030https://support.apple.com/kb/HT205031
2015-08-17
Published