Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2015-3784

CVE-2015-3784, Severity pending severity (CVSS —): 3 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
-
Exploitation
2.5 %

EPSS, predicted over 30 days

Tracked apps
3
Still exposed
0

Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS 2.50% above median percentile 83.6%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Keynote macOS com.apple.iWork.Keynote
    Affected ≤6.5 Fixed in > 6.5 Latest tracked - undetermined
  • Numbers macOS com.apple.iWork.Numbers
    Affected ≤3.5 Fixed in > 3.5 Latest tracked - undetermined
  • Pages macOS com.apple.iWork.Pages
    Affected ≤5.5.3 Fixed in > 5.5.3 Latest tracked - undetermined

NVD references 6 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (3)
Vendor Product Versions
apple numbers
All platforms (wildcard)
≤3.5
apple keynote
All platforms (wildcard)
≤6.5
apple pages
All platforms (wildcard)
≤5.5.3
View on NVD ↗ Advisory · lists.apple.com Advisory · support.apple.com