CVE-2015-5875: XSS
Published Oct 9, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Notes in Apple OS X before 10.11 allows local users to inject arbitrary web script or HTML via crafted text.
Affected Software
1 affected component
Apple iOS and macOS<=10.10.5
Event History
Oct 9, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5875?
CVE-2015-5875 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-5875?
To fix CVE-2015-5875, upgrade to OS X 10.11 or later, as Apple has patched this vulnerability in that version.
3
Who is affected by CVE-2015-5875?
Local users of Apple OS X versions prior to 10.11 are affected by CVE-2015-5875.
4
What types of attacks can be executed due to CVE-2015-5875?
CVE-2015-5875 allows local users to inject arbitrary web scripts or HTML, potentially leading to XSS attacks.
5
Is CVE-2015-5875 a remotely exploitable vulnerability?
CVE-2015-5875 is not remotely exploitable, as it requires local access to the affected systems.