Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-15026 | A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. An attack has to be approached locally. Upgrading to version 1.18 is able to address this issue. The patch is identified as 8c954e8d9f6f6863729e50105a8abf3f87fff74c. It is recommended to upgrade the affected component. VDB-221486 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2022-26260 | Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse(). Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse(). NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-22912 | Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution. Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2017-6438 | Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file. NVD description · AI analysis pending | 7.3 group max | <1% | PoC |
| — |