{"api_version":"1","generated_at":"2026-07-24T18:36:53+00:00","cve":"CVE-2015-7081","urls":{"html":"https://cve.report/CVE-2015-7081","api":"https://cve.report/api/cve/CVE-2015-7081.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-7081","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-7081"},"summary":{"title":"CVE-2015-7081","description":"iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","state":"PUBLISHED","assigner":"apple","published_at":"2015-12-11 11:59:46","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://support.apple.com/HT205637","name":"https://support.apple.com/HT205637","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2015-12-08-1 iOS 9.2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT205635","name":"https://support.apple.com/HT205635","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iOS 9.2 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1034344","name":"http://www.securitytracker.com/id/1034344","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple OS X Multiple Flaws Let Remote and Local Users Execute Arbitrary Code and Deny Service and Let Local Users Obtain Potentially Sensitive Information and Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html","name":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"APPLE-SA-2015-12-08-3 OS X El Capitan 10.11.2 and Security Update\t2015-008","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-7081","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7081","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"7081","vulnerable":"1","versionEndIncluding":"9.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7081","vulnerable":"1","versionEndIncluding":"10.11.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:36:35.244Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT205635"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT205637"},{"name":"1034344","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1034344"},{"name":"APPLE-SA-2015-12-08-3","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html"},{"name":"APPLE-SA-2015-12-08-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-12-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-12T09:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT205635"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT205637"},{"name":"1034344","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1034344"},{"name":"APPLE-SA-2015-12-08-3","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html"},{"name":"APPLE-SA-2015-12-08-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2015-7081","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://support.apple.com/HT205635","refsource":"CONFIRM","url":"https://support.apple.com/HT205635"},{"name":"https://support.apple.com/HT205637","refsource":"CONFIRM","url":"https://support.apple.com/HT205637"},{"name":"1034344","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1034344"},{"name":"APPLE-SA-2015-12-08-3","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html"},{"name":"APPLE-SA-2015-12-08-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2015-7081","datePublished":"2015-12-11T11:00:00.000Z","dateReserved":"2015-09-16T00:00:00.000Z","dateUpdated":"2024-08-06T07:36:35.244Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-12-11 11:59:46","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","versionEndIncluding":"10.11.1","matchCriteriaId":"767D7ECF-24C5-4605-9368-5A41456A475E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndIncluding":"9.1","matchCriteriaId":"04EA4C73-EC97-4FC8-9AA5-D9B4A3EA869C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"7081","Ordinal":"1","Title":"CVE-2015-7081","CVE":"CVE-2015-7081","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"7081","Ordinal":"1","NoteData":"iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","Type":"Description","Title":"CVE-2015-7081"},{"CveYear":"2015","CveId":"7081","Ordinal":"2","NoteData":"2015-12-11","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"7081","Ordinal":"3","NoteData":"2017-09-12","Type":"Other","Title":"Modified"}]}}}