Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 26 of 48
CVE-2011-0116P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0116 [HIGH] CWE-399 CVE-2011-0116: Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as use
Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to DOM manipulations during iTunes Store browsing, a differen
nvd
CVE-2011-0149P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0149 [HIGH] CWE-119 CVE-2011-0149: WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly parse HTML elements associ
WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly parse HTML elements associated with document namespaces, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to a "dangling pointer" and iTunes Store browsing, a different vul
nvd
CVE-2011-0132P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0132 [HIGH] CWE-399 CVE-2011-0132: Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1
Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vecto
nvd
CVE-2011-2866P4HIGHCVSS 7.6≤ 10.5.3v4.0.0+60 more2012-03-08
CVE-2011-2866 [HIGH] CWE-119 CVE-2011-2866: WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
nvd
CVE-2012-0636P4HIGHCVSS 7.6≤ 10.5.3v4.0.0+60 more2012-03-08
CVE-2012-0636 [HIGH] CWE-119 CVE-2012-0636: WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
nvd
CVE-2012-0638P4HIGHCVSS 7.6≤ 10.5.3v4.0.0+60 more2012-03-08
CVE-2012-0638 [HIGH] CWE-119 CVE-2012-0638: WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
nvd
CVE-2012-0637P4HIGHCVSS 7.6≤ 10.5.3v4.0.0+60 more2012-03-08
CVE-2012-0637 [HIGH] CWE-119 CVE-2012-0637: WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
nvd
CVE-2012-0639P4HIGHCVSS 7.6≤ 10.5.3v4.0.0+60 more2012-03-08
CVE-2012-0639 [HIGH] CWE-119 CVE-2012-0639: WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
nvd
CVE-2012-0648P4HIGHCVSS 7.6≤ 10.5.3v4.0.0+60 more2012-03-08
CVE-2012-0648 [HIGH] CWE-119 CVE-2012-0648: WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
nvd
CVE-2018-4319P3HIGHCVSS 8.1fixed in 12.92019-04-03
CVE-2018-4319 [HIGH] CWE-346 CVE-2018-4319: A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of se
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2012-0634P4HIGHCVSS 7.6≤ 10.5.3v4.0.0+60 more2012-03-08
CVE-2012-0634 [HIGH] CWE-119 CVE-2012-0634: WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
nvd
CVE-2011-2825P4CRITICALCVSS 9.3fixed in 10.62011-08-29
CVE-2011-2825 [CRITICAL] CWE-416 CVE-2011-2825: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving custom fonts.
nvd
CVE-2018-4188P3MEDIUMCVSS 6.5fixed in 12.7.52018-06-08
CVE-2018-4188 [MEDIUM] CWE-20 CVE-2018-4188: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2015-3414P4HIGHCVSS 7.5v12.62017-03-21
CVE-2015-3414 [HIGH] CVE-2015-3414: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2015-3414
Component: CVE-2015-3414
apple
CVE-2011-3237P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3237 [HIGH] CWE-119 CVE-2011-3237: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-3236P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3236 [HIGH] CWE-119 CVE-2011-3236: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-3235P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3235 [HIGH] CWE-119 CVE-2011-3235: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2356P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2356 [HIGH] CWE-119 CVE-2011-2356: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2354P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2354 [HIGH] CWE-119 CVE-2011-2354: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2352P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2352 [HIGH] CWE-119 CVE-2011-2352: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd