cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 27 of 48
CVE-2011-3244P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3244 [HIGH] CWE-119 CVE-2011-3244: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-3238P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3238 [HIGH] CWE-119 CVE-2011-3238: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2338P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+68 more2011-10-12
CVE-2011-2338 [HIGH] CWE-119 CVE-2011-2338: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2341P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2341 [HIGH] CWE-119 CVE-2011-2341: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2809P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2809 [HIGH] CWE-119 CVE-2011-2809: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-0259P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+68 more2011-10-12
CVE-2011-0259 [HIGH] CWE-119 CVE-2011-0259: CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
nvd
CVE-2011-3239P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3239 [HIGH] CWE-119 CVE-2011-3239: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-3233P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3233 [HIGH] CWE-119 CVE-2011-3233: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-3241P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-3241 [HIGH] CWE-119 CVE-2011-3241: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2815P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2815 [HIGH] CWE-119 CVE-2011-2815: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2814P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2814 [HIGH] CWE-119 CVE-2011-2814: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2816P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2816 [HIGH] CWE-119 CVE-2011-2816: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2817P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2817 [HIGH] CWE-119 CVE-2011-2817: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2820P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2820 [HIGH] CWE-119 CVE-2011-2820: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2339P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+68 more2011-10-12
CVE-2011-2339 [HIGH] CWE-119 CVE-2011-2339: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2813P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2813 [HIGH] CWE-119 CVE-2011-2813: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2831P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2831 [HIGH] CWE-119 CVE-2011-2831: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2011-2811P4HIGHCVSS 7.6≤ 10.4.1v4.0.0+56 more2011-10-12
CVE-2011-2811 [HIGH] CWE-119 CVE-2011-2811: WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.
nvd
CVE-2014-3192P4HIGHCVSS 7.5≤ 12.1.32014-10-08
CVE-2014-3192 [HIGH] CWE-416 CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/Pro Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvdapple
CVE-2015-5755P4MEDIUMCVSS 6.8≤ 12.22015-08-17
CVE-2015-5755 [MEDIUM] CWE-119 CVE-2015-5755: CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitr CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.
nvdapple