CVE-2015-7995: Apple iPhone OS
Medium severity, CVSS 5.0. EPSS: 4.2% chance of exploitation in the next 30 days.
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
Affected products
- Apple iPhone OS: up to and including 9.2
- Apple Mac OS X: up to and including 10.11.2
- Apple tvOS: up to and including 9.1
- Apple watchOS: up to and including 2.1
- Xmlsoft Libxslt: up to and including 1.1.28
Published 2015-11-17. Last modified 2026-06-17.