Libplist is a niche but well-embedded library that parses Apple plist data structures across a range of applications and devices; despite its narrow product scope, it occupies a critical role in iOS, macOS, and related ecosystem tooling. Its vulnerability profile centers on memory-safety and input-handling weaknesses—out-of-bounds reads and writes, integer overflows, and improper buffer-boundary enforcement—that are characteristic of C-based parser libraries handling untrusted format data. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libplist Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6438HIGH Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) an | Mar 15, 2017 | 7.3 | 23 | NO | NO |
CVE-2017-6440MEDIUM The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. | Mar 15, 2017 | 5.0 | 18 | NO | NO |
CVE-2017-6439MEDIUM Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via | Mar 15, 2017 | 5.0 | 18 | NO | NO |
CVE-2017-6437MEDIUM The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file. | Mar 15, 2017 | 5.0 | 18 | NO | NO |
CVE-2017-6435MEDIUM The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file. | Mar 15, 2017 | 5.0 | 17 | NO | NO |
CVE-2017-6436MEDIUM The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. | Mar 15, 2017 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libplist Project.
Media articles that mention a CVE ID that affects a product developed by Libplist Project — matched by CVE ID, not by vendor name.