NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Oct 8, 2014 | Sep 18, 2014 |
| Apple Osx Foundation | — | Upgrade macOS to the latest version | Sep 22, 2014 | Sep 18, 2014 |
| Apple Osx Note | — | Apply OS X security update 2014-004Upgrade macOS to the latest version | Aug 28, 2015 | Sep 18, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub