cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 19 of 48
CVE-2024-44193P3HIGHCVSS 7.8fixed in 12.13.32024-10-02
CVE-2024-44193 [HIGH] CWE-281 CVE-2024-44193: A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Wi A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privileges.
nvd
CVE-2019-8562P3CRITICALCVSS 9.6fixed in 12.9.42019-12-18
CVE-2019-8562 [CRITICAL] CWE-787 CVE-2019-8562: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, t A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2015-3416P3HIGHCVSS 7.5v12.62017-03-21
CVE-2015-3416 [HIGH] CVE-2015-3416: iTunes 12.6 Apple Security Update: About the security content of iTunes 12.6 Product: iTunes Version: 12.6 CVE: CVE-2015-3416 Component: CVE-2015-3416
apple
CVE-2018-4210P3HIGHCVSS 8.8fixed in 12.7.42019-01-11
CVE-2018-4210 [HIGH] CWE-129 CVE-2018-4210: In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 f In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.
nvd
CVE-2018-4376P3HIGHCVSS 8.8fixed in 12.9.12019-04-03
CVE-2018-4376 [HIGH] CWE-119 CVE-2018-4376: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2018-4375P3HIGHCVSS 8.8fixed in 12.9.12019-04-03
CVE-2018-4375 [HIGH] CWE-119 CVE-2018-4375: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2018-4269P3HIGHCVSS 8.6fixed in 12.82019-04-03
CVE-2018-4269 [HIGH] CWE-119 CVE-2018-4269: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2015-6992P3HIGHCVSS 7.5≤ 12.3.02015-10-23
CVE-2015-6992 [HIGH] CVE-2015-6992: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-7017.
nvdapple
CVE-2015-6975P3HIGHCVSS 7.5≤ 12.3.02015-10-23
CVE-2015-6975 [HIGH] CWE-119 CVE-2015-6975: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.
nvdapple
CVE-2017-7172P3HIGHCVSS 7.8fixed in 12.7.22018-04-03
CVE-2017-7172 [HIGH] CWE-119 CVE-2017-7172: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CFNetwork Session" component. It allows attackers to execute arbitra
nvd
CVE-2020-9862P3HIGHCVSS 7.8fixed in 12.10.82020-10-16
CVE-2020-9862 [HIGH] CWE-77 CVE-2020-9862: A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Copying a URL from Web Inspector may lead to command injection.
nvd
CVE-2012-0614P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0614 [CRITICAL] CWE-119 CVE-2012-0614: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0629P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0629 [CRITICAL] CWE-119 CVE-2012-0629: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0633P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0633 [CRITICAL] CWE-119 CVE-2012-0633: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0619P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0619 [CRITICAL] CWE-119 CVE-2012-0619: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0622P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0622 [CRITICAL] CWE-119 CVE-2012-0622: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0627P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0627 [CRITICAL] CWE-119 CVE-2012-0627: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0631P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0631 [CRITICAL] CWE-119 CVE-2012-0631: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0635P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0635 [CRITICAL] CWE-119 CVE-2012-0635: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0625P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0625 [CRITICAL] CWE-119 CVE-2012-0625: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
Apple Itunes vulnerabilities | cvebase