UIKit0 libplist XML xplist.c plist_from_xml xml external entity reference
Published Feb 21, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.72%
Description
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c of the component XML Handler. The manipulation leads to xml external entity reference. The patch is named c086cb139af7c82845f6d565e636073ff4b37440. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-221499.
Affected products
-
- Version 1.12StatusaffectedConstraints-
- Version
- 1.12
No data.
Red Hat Enterprise Linux 6
libplist
Out of support scope
Red Hat Enterprise Linux 7
libplist
Out of support scope
Red Hat Enterprise Linux 8
libplist
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libplist | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libplist | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | libplist | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2 other sources (Red Hat, CVE.org) ▾
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
AV:A/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.72% (0.00723) | 52.39th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.72% (0.00723) | 49.01th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.09% (0.00088) | 23.09th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.22% (0.00219) | 60.88th | v3 (v2023.03.01) |
| Mar 25, 2024 | 0.15% (0.00154) | 50.73th | v3 (v2023.03.01) |
| Feb 28, 2024 | 0.14% (0.00137) | 47.99th | v3 (v2023.03.01) |
| Jan 22, 2024 | 0.07% (0.00073) | 30.28th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00063) | 25.28th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Mar 3, 2023 | 0.95% (0.00954) | 36.36th | v2 (v2022.01.01) |
| Feb 21, 2023 | 0.89% (0.00890) | 30.05th | v2 (v2022.01.01) |
References (8)
- https://access.redhat.com/security/cve/CVE-2015-10082 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2174233 Issue Tracking
- https://github.com/UIKit0/libplist/commit/c086cb139af7c82845f6d565e636073ff4b37440 patch
- https://github.com/libimobiledevice/libplist/commit/c086cb139af7c82845f6d565e636073ff4b37440
- https://nvd.nist.gov/vuln/detail/CVE-2015-10082
- https://vuldb.com/?ctiid.221499 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.221499 vdb-entrytechnical-descriptionPermissions Required
- https://www.cve.org/CVERecord?id=CVE-2015-10082
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2015-10082 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2174233 | Issue Tracking | |
| https://github.com/UIKit0/libplist/commit/c086cb139af7c82845f6d565e636073ff4b37440 | patch | |
| https://github.com/libimobiledevice/libplist/commit/c086cb139af7c82845f6d565e636073ff4b37440 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2015-10082 | ||
| https://vuldb.com/?ctiid.221499 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.221499 | vdb-entrytechnical-descriptionPermissions Required | |
| https://www.cve.org/CVERecord?id=CVE-2015-10082 |
Change history (0)
No recorded changes yet.