cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 23 of 48
CVE-2020-3864P3HIGHCVSS 7.8fixed in 12.10.42020-10-27
CVE-2020-3864 [HIGH] CWE-346 CVE-2020-3864: A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17 A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
nvd
CVE-2023-32351P3HIGHCVSS 7.8fixed in 12.12.92023-06-23
CVE-2023-32351 [HIGH] CWE-276 CVE-2023-32351: A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges.
nvd
CVE-2022-48611P3HIGHCVSS 7.8fixed in 12.12.42024-04-26
CVE-2022-48611 [HIGH] CWE-693 CVE-2022-48611: A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges.
nvd
CVE-2010-1387P3CRITICALCVSS 9.3≤ 9.0.3v4.0.0+56 more2010-06-18
CVE-2010-1387 [CRITICAL] CWE-399 CVE-2010-1387: Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
nvd
CVE-2015-3717P3HIGHCVSS 7.5v12.62017-03-21
CVE-2015-3717 [HIGH] CVE-2015-3717: iTunes 12.6 Apple Security Update: About the security content of iTunes 12.6 Product: iTunes Version: 12.6 CVE: CVE-2015-3717 Component: CVE-2015-3717
apple
CVE-2018-4311P3HIGHCVSS 8.1fixed in 12.92019-04-03
CVE-2018-4311 [HIGH] CWE-200 CVE-2018-4311: The issue was addressed by removing origin information. This issue affected versions prior to iOS 12 The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2018-4126P3HIGHCVSS 7.8fixed in 12.92019-04-03
CVE-2018-4126 [HIGH] CWE-119 CVE-2018-4126: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2012-3632P3CRITICALCVSS 9.3≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3632 [CRITICAL] CWE-119 CVE-2012-3632: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2019-8848P3HIGHCVSS 7.8fixed in 12.10.32020-10-27
CVE-2019-8848 [HIGH] CVE-2019-8848: This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iClo This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An application may be able to gain elevated privileges.
nvd
CVE-2018-4474P3HIGHCVSS 7.5fixed in 12.92020-10-27
CVE-2018-4474 [HIGH] CWE-400 CVE-2018-4474: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iClou A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, watchOS 5, Safari 12, iOS 12, iTunes 12.9 for Windows, tvOS 12. Unexpected interaction causes an ASSERT failure.
nvd
CVE-2015-1283P3MEDIUMCVSS 6.8v12.62017-03-21
CVE-2015-1283 [MEDIUM] CVE-2015-1283: iTunes 12.6 Apple Security Update: About the security content of iTunes 12.6 Product: iTunes Version: 12.6 CVE: CVE-2015-1283 Component: CVE-2015-1283
apple
CVE-2022-22612P3HIGHCVSS 7.8fixed in 12.12.32022-03-18
CVE-2022-22612 [HIGH] CWE-787 CVE-2022-22612: A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.
nvd
CVE-2013-0992P3MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0992 [MEDIUM] CWE-399 CVE-2013-0992: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1003P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1003 [CRITICAL] CWE-399 CVE-2013-1003: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1006P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1006 [CRITICAL] CWE-399 CVE-2013-1006: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1004P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1004 [CRITICAL] CWE-399 CVE-2013-1004: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1008P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1008 [CRITICAL] CWE-399 CVE-2013-1008: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1001P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1001 [CRITICAL] CWE-399 CVE-2013-1001: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1000P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1000 [CRITICAL] CWE-119 CVE-2013-1000: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1005P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1005 [CRITICAL] CWE-399 CVE-2013-1005: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
Apple Itunes vulnerabilities | cvebase