cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 20 of 48
CVE-2012-0623P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0623 [CRITICAL] CWE-119 CVE-2012-0623: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0626P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0626 [CRITICAL] CWE-119 CVE-2012-0626: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0628P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0628 [CRITICAL] CWE-119 CVE-2012-0628: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0618P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0618 [CRITICAL] CWE-119 CVE-2012-0618: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0630P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0630 [CRITICAL] CWE-119 CVE-2012-0630: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0620P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0620 [CRITICAL] CWE-119 CVE-2012-0620: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0632P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0632 [CRITICAL] CWE-119 CVE-2012-0632: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0621P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0621 [CRITICAL] CWE-119 CVE-2012-0621: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2012-0624P3CRITICALCVSS 9.3fixed in 10.62012-03-08
CVE-2012-0624 [CRITICAL] CWE-119 CVE-2012-0624: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute a WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
nvd
CVE-2020-3826P3HIGHCVSS 7.8fixed in 12.10.42020-02-27
CVE-2020-3826 [HIGH] CWE-125 CVE-2020-3826: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2023-42938P3HIGHCVSS 7.8fixed in 12.13.12024-03-14
CVE-2023-42938 [HIGH] CWE-693 CVE-2023-42938: A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.
nvd
CVE-2016-5300P3HIGHCVSS 7.5v12.62017-03-21
CVE-2016-5300 [HIGH] CVE-2016-5300: iTunes 12.6 Apple Security Update: About the security content of iTunes 12.6 Product: iTunes Version: 12.6 CVE: CVE-2016-5300 Component: CVE-2016-5300
apple
CVE-2015-5874P3HIGHCVSS 7.5≤ 12.22015-09-18
CVE-2015-5874 [HIGH] CWE-119 CVE-2015-5874: CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary c CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvdapple
CVE-2010-3190P3HIGHCVSS 7.8v12.1.32010-08-31
CVE-2010-3190 [HIGH] CWE-426 CVE-2010-3190: Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Vis Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current
nvdapple
CVE-2015-7017P3HIGHCVSS 7.5≤ 12.3.02015-10-23
CVE-2015-7017 [HIGH] CVE-2015-7017: CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attack CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992.
nvdapple
CVE-2010-1777P3CRITICALCVSS 9.3≤ 9.2v1.0+65 more2010-07-30
CVE-2010-1777 [CRITICAL] CWE-119 CVE-2010-1777: Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or ca Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted itpc: URL.
nvd
CVE-2020-9794P3HIGHCVSS 8.1fixed in 12.10.72020-06-09
CVE-2020-9794 [HIGH] CWE-125 CVE-2020-9794: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A malicious application may cause a denial of service or potentially disclose memory contents.
nvd
CVE-2017-7022P3HIGHCVSS 7.8≤ 12.6.12017-07-20
CVE-2017-7022 [HIGH] CWE-119 CVE-2017-7022: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7025P3HIGHCVSS 7.8≤ 12.6.12017-07-20
CVE-2017-7025 [HIGH] CWE-119 CVE-2017-7025: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7023P3HIGHCVSS 7.8≤ 12.6.12017-07-20
CVE-2017-7023 [HIGH] CWE-119 CVE-2017-7023: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
Apple Itunes vulnerabilities | cvebase