Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 25 of 48
CVE-2018-4394P3HIGHCVSS 7.8fixed in 12.9.12019-04-03
CVE-2018-4394 [HIGH] CWE-119 CVE-2018-4394: A memory corruption issue was addressed with improved input validation. This issue affected versions
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1, iTunes 12.9.1.
nvd
CVE-2019-8801P3HIGHCVSS 7.8fixed in 12.10.22019-12-18
CVE-2019-8801 [HIGH] CWE-426 CVE-2019-8801: A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searc
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.
nvd
CVE-2015-3415P3HIGHCVSS 7.5v12.62017-03-21
CVE-2015-3415 [HIGH] CVE-2015-3415: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2015-3415
Component: CVE-2015-3415
apple
CVE-2007-3752P3CRITICALCVSS 9.3≤ 7.3.22007-09-06
CVE-2007-3752 [CRITICAL] CWE-119 CVE-2007-3752: Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of s
Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.
nvd
CVE-2011-0115P3HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0115 [HIGH] CWE-119 CVE-2011-0115: The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple S
The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash)
nvd
CVE-2014-4466P3HIGHCVSS 7.5≤ 12.12014-12-10
CVE-2014-4466 [HIGH] CWE-399 CVE-2014-4466: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvdapple
CVE-2019-8741P3HIGHCVSS 7.5fixed in 12.10.12020-02-28
CVE-2019-8741 [HIGH] CWE-835 CVE-2019-8741: A denial of service issue was addressed with improved input validation.
A denial of service issue was addressed with improved input validation.
nvd
CVE-2018-4347P3HIGHCVSS 7.8fixed in 12.92019-04-03
CVE-2018-4347 [HIGH] CWE-416 CVE-2018-4347: A use after free issue was addressed with improved memory management. This issue affected versions p
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2011-3926P3HIGHCVSS 7.5fixed in 10.72012-01-24
CVE-2011-3926 [HIGH] CWE-787 CVE-2011-3926: Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote att
Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-8542P3HIGHCVSS 7.8fixed in 12.9.42019-12-18
CVE-2019-8542 [HIGH] CWE-120 CVE-2019-8542: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macO
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.
nvd
CVE-2019-6221P3HIGHCVSS 7.8fixed in 12.9.32019-03-05
CVE-2019-6221 [HIGH] CWE-125 CVE-2019-6221: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, iTunes 12.9.3 for Windows. A malicious application may be able to elevate privileges.
nvd
CVE-2015-3688P3MEDIUMCVSS 6.8≤ 12.22015-07-03
CVE-2015-3688 [MEDIUM] CVE-2015-3688: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar
CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, and CVE-2015-3689.
nvdapple
CVE-2015-3686P3MEDIUMCVSS 6.8≤ 12.22015-07-03
CVE-2015-3686 [MEDIUM] CVE-2015-3686: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar
CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3687, CVE-2015-3688, and CVE-2015-3689.
nvdapple
CVE-2015-3687P3MEDIUMCVSS 6.8≤ 12.22015-07-03
CVE-2015-3687 [MEDIUM] CVE-2015-3687: CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrar
CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3688, and CVE-2015-3689.
nvdapple
CVE-2018-4117P3MEDIUMCVSS 6.5fixed in 12.7.42018-04-03
CVE-2018-4117 [MEDIUM] CWE-200 CVE-2018-4117: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy an
nvd
CVE-2009-3560P4MEDIUMCVSS 5.0v12.62017-03-21
CVE-2009-3560 [MEDIUM] CVE-2009-3560: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2009-3560
Component: CVE-2009-3560
apple
CVE-2019-8597P3MEDIUMCVSS 6.5fixed in 12.9.52019-12-18
CVE-2019-8597 [MEDIUM] CWE-787 CVE-2019-8597: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8615P3MEDIUMCVSS 6.5fixed in 12.9.52019-12-18
CVE-2019-8615 [MEDIUM] CWE-125 CVE-2019-8615: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2012-3703P4HIGHCVSS 8.3≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3703 [HIGH] CVE-2012-3703: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2009-3720P4MEDIUMCVSS 5.0v12.62017-03-21
CVE-2009-3720 [MEDIUM] CVE-2009-3720: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2009-3720
Component: CVE-2009-3720
apple