Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.72%—Libimobiledevice Libplist21/2/202317/6/2026
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is named c086cb139af7c82845f6d565e636073ff4b37440. It is recommended to…
ModificadaMedia (5.5)1.5%—Libimobiledevice Libplist20/4/201717/6/2026
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.
ModificadaAlta (7.5)2.7%—Libimobiledevice Libplist3/3/201717/6/2026
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.
ModificadaAlta (7.5)2.9%—Libimobiledevice Libplist3/3/201717/6/2026
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
ModificadaMedia (5.5)1.3%—Libimobiledevice Libplist3/3/201717/6/2026
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
ModificadaCrítica (9.1)3.8%—Libimobiledevice Libplist21/1/201717/6/2026
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.
ModificadaCrítica (9.1)2.9%—Libimobiledevice Libplist11/1/201717/6/2026
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.
ModificadaMedia (5.3)3.0%—LibimobiledeviceLibimobiledevice LibusbmuxdCanonical Ubuntu LinuxOpensuse Leap+113/6/201617/6/2026
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
ModificadaBaja (3.3)0.27%—Libimobiledevice19/1/201416/6/2026
userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.