CVE-2015-10082
- EPSS 0.13%
- Veröffentlicht 21.02.2023 07:15:10
- Zuletzt bearbeitet 21.11.2024 02:24:20
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is na...
CVE-2017-7982
- EPSS 0.4%
- Veröffentlicht 20.04.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.
CVE-2017-5834
- EPSS 0.5%
- Veröffentlicht 03.03.2017 15:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
CVE-2017-5835
- EPSS 0.73%
- Veröffentlicht 03.03.2017 15:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
CVE-2017-5836
- EPSS 0.45%
- Veröffentlicht 03.03.2017 15:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.
CVE-2017-5545
- EPSS 0.42%
- Veröffentlicht 21.01.2017 01:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.
CVE-2017-5209
- EPSS 0.38%
- Veröffentlicht 11.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.