cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 18 of 48
CVE-2016-4769P3HIGHCVSS 8.8≤ 12.4.32016-09-25
CVE-2016-4769 [HIGH] CWE-119 CVE-2016-4769: WebKit in Apple iTunes before 12.5.1 on Windows and Safari before 10 allows remote attackers to exec WebKit in Apple iTunes before 12.5.1 on Windows and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvd
CVE-2018-4437P3HIGHCVSS 8.8fixed in 12.9.22019-04-03
CVE-2018-4437 [HIGH] CWE-119 CVE-2018-4437: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2018-4464P3HIGHCVSS 8.8fixed in 12.9.22019-04-03
CVE-2018-4464 [HIGH] CWE-119 CVE-2018-4464: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2018-4392P3HIGHCVSS 8.8fixed in 12.9.12019-04-03
CVE-2018-4392 [HIGH] CWE-119 CVE-2018-4392: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2012-0592P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0592 [CRITICAL] CWE-119 CVE-2012-0592: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2011-0170P3CRITICALCVSS 9.3≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0170 [CRITICAL] CWE-119 CVE-2011-0170: Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile in a JPEG image.
nvd
CVE-2018-4144P3HIGHCVSS 7.8fixed in 12.7.42018-04-03
CVE-2018-4144 [HIGH] CWE-119 CVE-2018-4144: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Security" component. A buffer overflow allows attackers to execute a
nvd
CVE-2020-27917P3HIGHCVSS 7.8fixed in 12.112020-12-08
CVE-2020-27917 [HIGH] CWE-416 CVE-2020-27917: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2020-9961P3HIGHCVSS 7.8fixed in 12.10.92020-10-27
CVE-2020-9961 [HIGH] CWE-125 CVE-2020-9961: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9981P3HIGHCVSS 7.8fixed in 12.10.92020-12-08
CVE-2020-9981 [HIGH] CWE-416 CVE-2020-9981: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted file may lead to arbitrary code
nvd
CVE-2020-9877P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9877 [HIGH] CWE-125 CVE-2020-9877: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9872P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9872 [HIGH] CWE-787 CVE-2020-9872: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9937P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9937 [HIGH] CWE-787 CVE-2020-9937: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9871P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9871 [HIGH] CWE-787 CVE-2020-9871: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9936P3HIGHCVSS 7.8fixed in 12.10.82020-10-16
CVE-2020-9936 [HIGH] CWE-787 CVE-2020-9936: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9875P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9875 [HIGH] CWE-190 CVE-2020-9875: An integer overflow was addressed through improved input validation. This issue is fixed in iOS 13.6 An integer overflow was addressed through improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9874P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9874 [HIGH] CWE-787 CVE-2020-9874: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9879P3HIGHCVSS 7.8fixed in 12.10.82020-10-22
CVE-2020-9879 [HIGH] CWE-787 CVE-2020-9879: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2016-4447P3HIGHCVSS 7.5v12.4.12016-06-09
CVE-2016-4447 [HIGH] CWE-119 CVE-2016-4447: The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attack The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
nvd
CVE-2022-22611P3HIGHCVSS 7.8fixed in 12.12.32022-03-18
CVE-2022-22611 [HIGH] CWE-125 CVE-2022-22611: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15.4 An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
Apple Itunes vulnerabilities | cvebase