{"api_version":"1","generated_at":"2026-07-23T06:22:29+00:00","cve":"CVE-2015-1092","urls":{"html":"https://cve.report/CVE-2015-1092","api":"https://cve.report/api/cve/CVE-2015-1092.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1092","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1092"},"summary":{"title":"CVE-2015-1092","description":"NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","state":"PUBLISHED","assigner":"apple","published_at":"2015-04-10 14:59:08","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://support.apple.com/kb/HT204870","name":"https://support.apple.com/kb/HT204870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Watch OS 1.0.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT204661","name":"https://support.apple.com/HT204661","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iOS 8.3 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html","name":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2015-04-08-4 Apple TV 7.2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/73983","name":"http://www.securityfocus.com/bid/73983","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple iOS and TV Multiple Information Disclosure Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1032050","name":"http://www.securitytracker.com/id/1032050","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple iOS Bugs Let Remote Users Execute Arbitrary Code and Local Users Access Information and Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT204662","name":"https://support.apple.com/HT204662","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of Apple TV 7.2 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2015-04-08-3 iOS 8.3","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1092","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1092","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1092","vulnerable":"1","versionEndIncluding":"8.2","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1092","vulnerable":"1","versionEndIncluding":"7.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"tvos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:33:20.404Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/kb/HT204870"},{"name":"APPLE-SA-2015-04-08-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html"},{"name":"73983","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/73983"},{"name":"1032050","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1032050"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT204662"},{"name":"APPLE-SA-2015-04-08-4","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT204661"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-04-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-30T15:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/kb/HT204870"},{"name":"APPLE-SA-2015-04-08-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html"},{"name":"73983","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/73983"},{"name":"1032050","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1032050"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT204662"},{"name":"APPLE-SA-2015-04-08-4","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT204661"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2015-1092","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://support.apple.com/kb/HT204870","refsource":"CONFIRM","url":"https://support.apple.com/kb/HT204870"},{"name":"APPLE-SA-2015-04-08-3","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html"},{"name":"73983","refsource":"BID","url":"http://www.securityfocus.com/bid/73983"},{"name":"1032050","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1032050"},{"name":"https://support.apple.com/HT204662","refsource":"CONFIRM","url":"https://support.apple.com/HT204662"},{"name":"APPLE-SA-2015-04-08-4","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html"},{"name":"https://support.apple.com/HT204661","refsource":"CONFIRM","url":"https://support.apple.com/HT204661"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2015-1092","datePublished":"2015-04-10T14:00:00.000Z","dateReserved":"2015-01-16T00:00:00.000Z","dateUpdated":"2024-08-06T04:33:20.404Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-04-10 14:59:08","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1","matchCriteriaId":"B98C1F4A-0A10-42CF-ABD5-A2248D55C7F0"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndIncluding":"8.2","matchCriteriaId":"C0340315-35F7-4736-854B-852916D00673"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1092","Ordinal":"1","Title":"CVE-2015-1092","CVE":"CVE-2015-1092","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1092","Ordinal":"1","NoteData":"NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","Type":"Description","Title":"CVE-2015-1092"},{"CveYear":"2015","CveId":"1092","Ordinal":"2","NoteData":"2015-04-10","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1092","Ordinal":"3","NoteData":"2016-12-30","Type":"Other","Title":"Modified"}]}}}