cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 17 of 48
CVE-2018-4265P3HIGHCVSS 8.8fixed in 12.82019-04-03
CVE-2018-4265 [HIGH] CWE-119 CVE-2018-4265: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4263P3HIGHCVSS 8.8fixed in 12.82019-04-03
CVE-2018-4263 [HIGH] CWE-119 CVE-2018-4263: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4267P3HIGHCVSS 8.8fixed in 12.82019-04-03
CVE-2018-4267 [HIGH] CWE-119 CVE-2018-4267: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4373P3HIGHCVSS 8.8fixed in 12.9.12019-04-03
CVE-2018-4373 [HIGH] CWE-119 CVE-2018-4373: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2018-4284P3HIGHCVSS 8.8fixed in 12.82019-04-03
CVE-2018-4284 [HIGH] CWE-704 CVE-2018-4284: A type confusion issue was addressed with improved memory handling. This issue affected versions pri A type confusion issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2011-3219P3CRITICALCVSS 9.3≤ 10.4.1v4.0.0+68 more2011-10-12
CVE-2011-3219 [CRITICAL] CWE-119 CVE-2011-3219: Buffer overflow in CoreMedia, as used in Apple iTunes before 10.5, allows remote attackers to execut Buffer overflow in CoreMedia, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2015-5922P3CRITICALCVSS 10.0v12.3
CVE-2015-5922 [CRITICAL] CVE-2015-5922: iTunes 12.3 Apple Security Update: About the security content of iTunes 12.3 Product: iTunes Version: 12.3 CVE: CVE-2015-5922 Component: CVE-ID Impact: Opening a media file may lead to arbitrary code execution Description: A security issue existed in Microsoft Foundation Class's handling of library loading. This issue was addressed by updating to the latest version of the Microsoft Visual C++ Redistributable Package.
apple
CVE-2020-27918P3HIGHCVSS 7.8fixed in 12.112020-12-08
CVE-2020-27918 [HIGH] CWE-416 CVE-2020-27918: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-9873P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9873 [HIGH] CWE-125 CVE-2020-9873: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9938P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9938 [HIGH] CWE-125 CVE-2020-9938: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9984P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9984 [HIGH] CWE-125 CVE-2020-9984: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2017-7090P3HIGHCVSS 7.5≤ 12.6.22017-10-23
CVE-2017-7090 [HIGH] CWE-200 CVE-2017-7090: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive cookie inf
nvd
CVE-2010-1769P3CRITICALCVSS 10.0≤ 9.1.1v7.0.0+36 more2010-06-18
CVE-2010-1769 [CRITICAL] CVE-2010-1769: WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, a WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.
nvd
CVE-2018-20505P3HIGHCVSS 7.5fixed in 12.9.32019-04-03
CVE-2018-20505 [HIGH] CWE-89 CVE-2018-20505: SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
nvd
CVE-2018-4214P3HIGHCVSS 8.8fixed in 12.7.52018-06-08
CVE-2018-4214 [HIGH] CWE-119 CVE-2018-4214: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to cause a denial of
nvd
CVE-2018-4209P3HIGHCVSS 8.8fixed in 12.7.42019-01-11
CVE-2018-4209 [HIGH] CWE-20 CVE-2018-4209: In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS bef In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
nvd
CVE-2018-4208P3HIGHCVSS 8.8fixed in 12.7.42019-01-11
CVE-2018-4208 [HIGH] CWE-20 CVE-2018-4208: In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS bef In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
nvd
CVE-2018-4212P3HIGHCVSS 8.8fixed in 12.7.42019-01-11
CVE-2018-4212 [HIGH] CVE-2018-4212: In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS bef In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
nvd
CVE-2018-4207P3HIGHCVSS 8.8fixed in 12.7.42019-01-11
CVE-2018-4207 [HIGH] CWE-20 CVE-2018-4207: In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS bef In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
nvd
CVE-2018-4213P3HIGHCVSS 8.8fixed in 12.7.42019-01-11
CVE-2018-4213 [HIGH] CWE-20 CVE-2018-4213: In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS bef In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
nvd
Apple Itunes vulnerabilities | cvebase