← Back

Libimobiledevice

libimobiledevice

9 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Libplist
libplist
Libusbmuxd
libusbmuxd

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Libimobiledevice
1Libplist
Nov 21, 2024
Feb 21, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external ent...Show more
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is named c086cb139af7c82845f6d565e636073ff4b37440. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221499.Show less
1Libimobiledevice
1Libplist
May 13, 2026
Apr 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a cr...Show more
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.Show less
1Libimobiledevice
1Libplist
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.
1Libimobiledevice
1Libplist
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
1Libimobiledevice
1Libplist
May 13, 2026
Mar 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
1Libimobiledevice
1Libplist
May 13, 2026
Jan 21, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data...Show more
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.Show less
1Libimobiledevice
1Libplist
May 6, 2026
Jan 11, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple...Show more
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.Show less
3Canonical
LibimobiledeviceOpensuse
5Leap
LibimobiledeviceLibusbmuxd+2 more
May 6, 2026
Jun 13, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP so...Show more
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.Show less
1Libimobiledevice
1Libimobiledevice
Apr 29, 2026
Jan 19, 2014
N/A· v4
N/A· v3
3.3 LOW· v2
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobilede...Show more
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.Show less