CVE-2014-4374: Medium severity Apple iOS and macOS vulnerability
NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4374?
The severity of CVE-2014-4374 is considered high due to its potential for unauthorized access to arbitrary files.
What systems are affected by CVE-2014-4374?
CVE-2014-4374 affects Apple iOS versions before 8 and older versions of macOS up to 10.9.4.
How do I fix CVE-2014-4374?
To fix CVE-2014-4374, update your Apple device to the latest version of iOS or macOS provided by Apple.
What type of vulnerability is CVE-2014-4374?
CVE-2014-4374 is an XML External Entity (XXE) vulnerability that allows attackers to read arbitrary files.
What are the potential impacts of exploiting CVE-2014-4374?
Exploiting CVE-2014-4374 could lead to unauthorized disclosure of sensitive information stored on the affected device.