Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 30 of 48
CVE-2011-0120P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0120 [HIGH] CWE-119 CVE-2011-0120: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0137P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0137 [HIGH] CWE-119 CVE-2011-0137: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0118P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0118 [HIGH] CWE-119 CVE-2011-0118: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0124P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0124 [HIGH] CWE-119 CVE-2011-0124: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0150P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0150 [HIGH] CWE-119 CVE-2011-0150: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0147P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0147 [HIGH] CWE-119 CVE-2011-0147: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0131P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0131 [HIGH] CWE-119 CVE-2011-0131: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0168P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0168 [HIGH] CWE-119 CVE-2011-0168: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0112P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0112 [HIGH] CWE-119 CVE-2011-0112: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0156P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0156 [HIGH] CWE-119 CVE-2011-0156: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0138P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0138 [HIGH] CWE-119 CVE-2011-0138: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0136P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0136 [HIGH] CWE-119 CVE-2011-0136: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0165P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0165 [HIGH] CWE-119 CVE-2011-0165: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-0139P4HIGHCVSS 7.6≤ 10.1.2v4.0.0+63 more2011-03-03
CVE-2011-0139 [HIGH] CWE-119 CVE-2011-0139: WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execut
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
nvd
CVE-2011-3064P4HIGHCVSS 7.5fixed in 10.72012-03-30
CVE-2011-3064 [HIGH] CWE-416 CVE-2011-3064: Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.
nvd
CVE-2011-1293P4HIGHCVSS 7.5fixed in 10.52011-03-25
CVE-2011-1293 [HIGH] CWE-416 CVE-2011-1293: Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.2
Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3081P4CRITICALCVSS 9.3fixed in 10.72012-05-01
CVE-2011-3081 [CRITICAL] CVE-2011-3081: Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3078.
nvd
CVE-2015-1122P4MEDIUMCVSS 6.8≤ 12.12015-04-10
CVE-2015-1122 [MEDIUM] CVE-2015-1122: WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x bef
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, A
nvdapple
CVE-2015-1120P4MEDIUMCVSS 6.8≤ 12.12015-04-10
CVE-2015-1120 [MEDIUM] CVE-2015-1120: WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x bef
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, A
nvdapple
CVE-2015-5822P4MEDIUMCVSS 6.8≤ 12.22015-09-18
CVE-2015-5822 [MEDIUM] CWE-119 CVE-2015-5822: WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attack
WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
nvdapple