CVE-2025-43235
published 2025-07-30CVE-2025-43235: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.19%
9.3th percentile
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 15.6 | 15.6 |
| apple | macos_sequoia | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-96fp-5vvq-h9wg: The issue was addressed with improved memory handling
ghsa_unreviewed·2025-07-30
CVE-2025-43235 [MEDIUM] CWE-400 GHSA-96fp-5vvq-h9wg: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.
Apple
CVE-2025-43235: macOS Sequoia 15.6
vendor_apple·2025-07-29·CVSS 5.5
CVE-2025-43235 [MEDIUM] CVE-2025-43235: macOS Sequoia 15.6
Apple Security Update: About the security content of macOS Sequoia 15.6
Product: macOS Sequoia
Version: 15.6
CVE: CVE-2025-43235
Component: Power Management
Impact: An app may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
Suricata
ET WEB_SPECIFIC_APPS D-Link SetWifiDownSettings Multiple XML Tags Buffer Overflow Attempt (CVE-2023-43235)
suricata·2025-10-10·CVSS 9.8
CVE-2023-43235 [CRITICAL] ET WEB_SPECIFIC_APPS D-Link SetWifiDownSettings Multiple XML Tags Buffer Overflow Attempt (CVE-2023-43235)
ET WEB_SPECIFIC_APPS D-Link SetWifiDownSettings Multiple XML Tags Buffer Overflow Attempt (CVE-2023-43235)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link SetWifiDownSettings Multiple XML Tags Buffer Overflow Attempt (CVE-2023-43235)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/HNAP1"; http.request_body; content:"|3c 3f|xml|20|version|3d 22|1.0|22|"; content:"|3c|SetWifiDownSettings"; fast_pattern; pcre:"/\x3c(?:StartTime|EndTime)\x3e[^\x3e]{100,}(?:\x3e|$)/"; reference:cve,2023-43235; classtype:web-application-attack; sid:2065145; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_10, cve CVE_2023_43235, deployment Perimeter, deployment Internal, performance_imp
No public exploits indexed.
No writeups or analysis indexed.
2025-07-30
Published