ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-7982
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

NVD description · AI analysis pending
5.51%
  • libimobiledevice libplist
CVE-2017-5835
+2 in the same advisory: …5836 …5834
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.

libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.

NVD description · AI analysis pending
7.5
group max
3%
  • libimobiledevice libplist
CVE-2017-5545
The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denia

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

NVD description · AI analysis pending
9.14%
  • libimobiledevice libplist
CVE-2017-5209
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a

The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.

NVD description · AI analysis pending
9.13%
  • libimobiledevice libplist
CVE-2016-5104
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.

NVD description · AI analysis pending
5.33%
  • libimobiledevice libimobiledevice
  • libimobiledevice libusbmuxd
  • libimobiledevice ubuntu linux
  • +1 more