Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 24 of 48
CVE-2013-0999P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0999 [CRITICAL] CWE-119 CVE-2013-0999: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1007P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1007 [CRITICAL] CWE-399 CVE-2013-1007: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1002P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1002 [CRITICAL] CWE-399 CVE-2013-1002: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1010P3CRITICALCVSS 9.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1010 [CRITICAL] CWE-399 CVE-2013-1010: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2022-26774P3HIGHCVSS 7.8fixed in 12.12.42022-05-26
CVE-2022-26774 [HIGH] CWE-693 CVE-2022-26774: A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 fo
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges.
nvd
CVE-2015-1157P3HIGHCVSS 7.8≤ 12.22015-05-28
CVE-2015-1157 [HIGH] CWE-17 CVE-2015-1157: CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot a
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
nvdapple
CVE-2011-0133P3HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0133 [HIGH] CWE-119 CVE-2011-0133: WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during l
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with pseudo-elements, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a di
nvd
CVE-2014-4459P3MEDIUMCVSS 6.8fixed in 12.22014-11-18
CVE-2014-4459 [MEDIUM] CVE-2014-4459: Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attacker
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
nvdapple
CVE-2012-3607P3CRITICALCVSS 9.3≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3607 [CRITICAL] CWE-119 CVE-2012-3607: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3606P3CRITICALCVSS 9.3≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3606 [CRITICAL] CWE-119 CVE-2012-3606: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3687P3CRITICALCVSS 9.3≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3687 [CRITICAL] CWE-119 CVE-2012-3687: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3621P3CRITICALCVSS 9.3≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3621 [CRITICAL] CWE-119 CVE-2012-3621: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3701P3CRITICALCVSS 9.3≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3701 [CRITICAL] CWE-119 CVE-2012-3701: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2010-4494P3HIGHCVSS 7.5fixed in 10.22010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2010-1763P3CRITICALCVSS 10.0≤ 9.1.1v7.0.0+36 more2010-06-18
CVE-2010-1763 [CRITICAL] CVE-2010-1763: Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and att
Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769.
nvd
CVE-2005-4092P3HIGHCVSS 7.5v6.0.12005-12-08
CVE-2005-4092 [HIGH] CWE-119 CVE-2005-4092: Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0
Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and
nvd
CVE-2008-3434P3HIGHCVSS 7.5≤ 6.0.5v1.0+28 more2008-08-01
CVE-2008-3434 [HIGH] CWE-94 CVE-2008-3434: Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
nvd
CVE-2017-7053P3HIGHCVSS 7.8≤ 12.6.12017-07-20
CVE-2017-7053 [HIGH] CVE-2017-7053: An issue was discovered in certain Apple products. iTunes before 12.6.2 on Windows is affected. The
An issue was discovered in certain Apple products. iTunes before 12.6.2 on Windows is affected. The issue involves the "iTunes" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4412P3HIGHCVSS 7.8fixed in 12.92019-04-03
CVE-2018-4412 [HIGH] CWE-119 CVE-2018-4412: A memory corruption issue was addressed with improved input validation. This issue affected versions
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2018-4414P3HIGHCVSS 7.8fixed in 12.92019-04-03
CVE-2018-4414 [HIGH] CWE-119 CVE-2018-4414: A memory corruption issue was addressed with improved input validation. This issue affected versions
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd