Записи libimobiledevice
9 опубликованных записей вендора libimobiledevice.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read3
- CWE-190 Integer Overflow or Wraparound1
- CWE-284 Improper Access Control1
- CWE-415 Double Free1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2015-10082Эксплойта нет | UIKit0 libplist XML xplist.c plist_from_xml xml external entity referencelibimobiledevice · libplist · CWE-611 | Критическая9,8 | — | 0,7 % | 21 февр. 2023 г. |
37Наблюдать | CVE-2017-5545Эксплойта нет | The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memlibimobiledevice · libplist · CWE-125 | Критическая9,1 | — | 3,8 % | 20 янв. 2017 г. |
37Наблюдать | CVE-2017-5209Эксплойта нет | The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from proceslibimobiledevice · libplist · CWE-125 | Критическая9,1 | — | 2,9 % | 11 янв. 2017 г. |
31Наблюдать | CVE-2017-5835Эксплойта нет | libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.libimobiledevice · libplist · CWE-770 | Высокая7,5 | — | 2,9 % | 3 мар. 2017 г. |
31Наблюдать | CVE-2017-5836Эксплойта нет | The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer nlibimobiledevice · libplist · CWE-415 | Высокая7,5 | — | 2,7 % | 3 мар. 2017 г. |
22Наблюдать | CVE-2016-5104Эксплойта нет | The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictilibimobiledevice · libimobiledevice · CWE-284 | Средняя5,3 | — | 3,0 % | 13 июн. 2016 г. |
22Наблюдать | CVE-2017-7982Эксплойта нет | Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause libimobiledevice · libplist · CWE-190 | Средняя5,5 | — | 1,5 % | 20 апр. 2017 г. |
22Наблюдать | CVE-2017-5834Эксплойта нет | The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via alibimobiledevice · libplist · CWE-125 | Средняя5,5 | — | 1,3 % | 3 мар. 2017 г. |
13Наблюдать | CVE-2013-2142Эксплойта нет | userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlibimobiledevice · libimobiledevice · CWE-59 | Низкая3,3 | — | 0,3 % | 19 янв. 2014 г. |
- CVE-2015-1008239Наблюдать
UIKit0 libplist XML xplist.c plist_from_xml xml external entity reference
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %libimobiledevice · libplist21 февр. 2023 г.
- CVE-2017-554537Наблюдать
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process mem
КритическаяCVSS 9,1Эксплойта нетEPSS 4 %libimobiledevice · libplist20 янв. 2017 г.
- CVE-2017-520937Наблюдать
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from proces
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %libimobiledevice · libplist11 янв. 2017 г.
- CVE-2017-583531Наблюдать
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libimobiledevice · libplist3 мар. 2017 г.
- CVE-2017-583631Наблюдать
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer n
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libimobiledevice · libplist3 мар. 2017 г.
- CVE-2016-510422Наблюдать
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restricti
СредняяCVSS 5,3Эксплойта нетEPSS 3 %libimobiledevice · libimobiledevice13 июн. 2016 г.
- CVE-2017-798222Наблюдать
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause
СредняяCVSS 5,5Эксплойта нетEPSS 1 %libimobiledevice · libplist20 апр. 2017 г.
- CVE-2017-583422Наблюдать
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a
СредняяCVSS 5,5Эксплойта нетEPSS 1 %libimobiledevice · libplist3 мар. 2017 г.
- CVE-2013-214213Наблюдать
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a sym
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %libimobiledevice · libimobiledevice19 янв. 2014 г.