CVE-2010-1777
published 2010-07-30CVE-2010-1777: Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.98%
91.3th percentile
Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted itpc: URL.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | <= 9.2 | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
| apple | itunes | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmfw-pf7r-rv62: Buffer overflow in Apple iTunes before 9
ghsa_unreviewed·2022-05-17
CVE-2010-1777 [HIGH] CWE-119 GHSA-gmfw-pf7r-rv62: Buffer overflow in Apple iTunes before 9
Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted itpc: URL.
Red Hat
kernel: Driver-Core: devtmpfs - set root directory mode to 0755
vendor_redhat·2009-10-30·CVSS 4.6
CVE-2010-0299 [MEDIUM] CWE-732 kernel: Driver-Core: devtmpfs - set root directory mode to 0755
kernel: Driver-Core: devtmpfs - set root directory mode to 0755
openSUSE 11.2 installs the devtmpfs root directory with insecure permissions (1777), which allows local users to gain privileges via unspecified vectors.
Statement: Not vulnerable. The Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, 5 and Red Hat Enterprise MRG did not include support for Devtmpfs, and therefore are not affected by this issue.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Jul/msg00000.htmlhttp://support.apple.com/kb/HT4263https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6988http://lists.apple.com/archives/security-announce/2010//Jul/msg00000.htmlhttp://support.apple.com/kb/HT4263https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6988
2010-07-30
Published