CVE-2015-7995

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2015
Last modified:
12/04/2025

Description

The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 9.2 (including)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.11.2 (including)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 9.1 (including)
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* 2.1 (including)
cpe:2.3:a:xmlsoft:libxslt:*:*:*:*:*:*:*:* 1.1.28 (including)


References to Advisories, Solutions, and Tools