VulnerabilityModified
CVE-2014-4374
NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
MEDIUM 5.0EPSS 2.19%
Does this matter?
Lower severity and a low EPSS score (2.19%). Track it; it rarely justifies an emergency change on its own.
Description
NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x · apple/iphone os
- Source
- product-security@apple.com
References
- http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlVendor Advisory
- http://support.apple.com/kb/HT6441
- http://support.apple.com/kb/HT6443Vendor Advisory
- http://www.securityfocus.com/bid/69882
- http://www.securityfocus.com/bid/69905
- http://www.securitytracker.com/id/1030866
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96077
- http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.htmlVendor Advisory
- http://support.apple.com/kb/HT6441
- http://support.apple.com/kb/HT6443Vendor Advisory
- http://www.securityfocus.com/bid/69882
- http://www.securityfocus.com/bid/69905
- http://www.securitytracker.com/id/1030866
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96077
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.