Vulnerability Name: | CVE-2015-1092 (CCN-102230) | ||||||||
Assigned: | 2015-04-08 | ||||||||
Published: | 2015-04-08 | ||||||||
Updated: | 2019-03-08 | ||||||||
Summary: | NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. CWE-611: Improper Restriction of XML External Entity Reference ('XXE') | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-1092 Source: APPLE Type: Vendor Advisory APPLE-SA-2015-04-08-3 Source: APPLE Type: Vendor Advisory APPLE-SA-2015-04-08-4 Source: BID Type: UNKNOWN 73983 Source: CCN Type: BID-73983 Apple iOS and TV Multiple Information Disclosure Vulnerabilities Source: SECTRACK Type: UNKNOWN 1032050 Source: XF Type: UNKNOWN appleios-cve20151092-info-disc(102230) Source: CCN Type: Apple Web site About the security content of iOS 8.3 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT204661 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT204662 Source: CONFIRM Type: UNKNOWN https://support.apple.com/kb/HT204870 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |