Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-0677Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Itunes

Severity
9.3CRITICALNVD
EPSS
15.8%
top 5.26%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 12
Latest updateMay 17

Description

Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDapple/itunes10.6.1+20

🔴Vulnerability Details

1
GHSA
GHSA-w699-h5p9-7m5f: Heap-based buffer overflow in Apple iTunes before 102022-05-17

💥Exploits & PoCs

2
Exploit-DB
Apple iTunes 10 - Extended M3U Stack Buffer Overflow (Metasploit)2012-06-25
Exploit-DB
Apple iTunes 10.6.1.7 - '.m3u' Walking Heap Buffer Overflow (PoC)2012-06-13