CVE-2015-7081
published 2015-12-11CVE-2015-7081: iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.11%
79.9th percentile
iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.1 | — |
| apple | mac_os_x | <= 10.11.1 | — |
| apple | os_x_el_capitan_10.11.2_security_update_2015-005_yosemite_and_security_update_20 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-7081: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
vendor_apple·CVSS 5.0
CVE-2015-7081 [MEDIUM] CVE-2015-7081: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Product: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
CVE: CVE-2015-7081
Component: CVE-ID
Apple
CVE-2015-7081: iOS 9.2
vendor_apple·CVSS 5.0
CVE-2015-7081 [MEDIUM] CVE-2015-7081: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7081
Component: CVE-ID
GHSA
GHSA-gx54-m73v-25x3: iBooks in Apple iOS before 9
ghsa_unreviewed·2022-05-17
CVE-2015-7081 [MEDIUM] GHSA-gx54-m73v-25x3: iBooks in Apple iOS before 9
iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://www.securitytracker.com/id/1034344https://support.apple.com/HT205635https://support.apple.com/HT205637http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://www.securitytracker.com/id/1034344https://support.apple.com/HT205635https://support.apple.com/HT205637
2015-12-11
Published