CVE-2015-10082
- EPSS 0.05%
- Veröffentlicht 21.02.2023 07:15:10
- Zuletzt bearbeitet 21.11.2024 02:24:20
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is na...
CVE-2017-7982
- EPSS 0.21%
- Veröffentlicht 20.04.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.
CVE-2017-5834
- EPSS 0.32%
- Veröffentlicht 03.03.2017 15:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
CVE-2017-5835
- EPSS 0.63%
- Veröffentlicht 03.03.2017 15:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
CVE-2017-5836
- EPSS 0.28%
- Veröffentlicht 03.03.2017 15:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.
CVE-2017-5545
- EPSS 0.26%
- Veröffentlicht 21.01.2017 01:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.
CVE-2017-5209
- EPSS 0.2%
- Veröffentlicht 11.01.2017 16:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.