CVE-2015-7995

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-11-17 15:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-7995

Mitre link : CVE-2015-7995

CVE.ORG link : CVE-2015-7995


JSON object : View

Products Affected

apple

  • iphone_os
  • tvos
  • mac_os_x
  • watchos

xmlsoft

  • libxslt