cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 35 of 48
CVE-2015-5823P4MEDIUMCVSS 6.8≤ 12.22015-09-18
CVE-2015-5823 [MEDIUM] CWE-119 CVE-2015-5823: WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attack WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
nvdapple
CVE-2015-7104P4MEDIUMCVSS 6.8v12.3.2
CVE-2015-7104 [MEDIUM] CVE-2015-7104: iTunes 12.3.2 Apple Security Update: About the security content of iTunes 12.3.2 Product: iTunes Version: 12.3.2 CVE: CVE-2015-7104 Component: CVE-ID
apple
CVE-2013-0994P4MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0994 [MEDIUM] CWE-399 CVE-2013-0994: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2015-3737P4MEDIUMCVSS 6.8≤ 12.22015-08-16
CVE-2015-3737 [MEDIUM] CWE-119 CVE-2015-3737: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvdapple
CVE-2015-3734P4MEDIUMCVSS 6.8≤ 12.22015-08-16
CVE-2015-3734 [MEDIUM] CWE-119 CVE-2015-3734: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvdapple
CVE-2015-3736P4MEDIUMCVSS 6.8≤ 12.22015-08-16
CVE-2015-3736 [MEDIUM] CWE-119 CVE-2015-3736: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvdapple
CVE-2015-3733P4MEDIUMCVSS 6.8≤ 12.22015-08-16
CVE-2015-3733 [MEDIUM] CWE-119 CVE-2015-3733: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvdapple
CVE-2015-3739P4MEDIUMCVSS 6.8≤ 12.22015-08-16
CVE-2015-3739 [MEDIUM] CWE-119 CVE-2015-3739: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvdapple
CVE-2015-3735P4MEDIUMCVSS 6.8v12.22015-08-16
CVE-2015-3735 [MEDIUM] CWE-119 CVE-2015-3735: WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-
nvdapple
CVE-2015-1154P4MEDIUMCVSS 6.8≤ 12.12015-05-08
CVE-2015-1154 [MEDIUM] CVE-2015-1154: WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1152 and CVE-2015-1153.
nvdapple
CVE-2013-0998P4MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0998 [MEDIUM] CWE-399 CVE-2013-0998: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-0995P4MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0995 [MEDIUM] CWE-399 CVE-2013-0995: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-0991P4MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0991 [MEDIUM] CWE-399 CVE-2013-0991: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-0993P4MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0993 [MEDIUM] CWE-399 CVE-2013-0993: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-0996P4MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-0996 [MEDIUM] CWE-399 CVE-2013-0996: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2015-6607P4MEDIUMCVSS 6.8v12.62017-03-21
CVE-2015-6607 [MEDIUM] CVE-2015-6607: iTunes 12.6 Apple Security Update: About the security content of iTunes 12.6 Product: iTunes Version: 12.6 CVE: CVE-2015-6607 Component: CVE-2015-6607
apple
CVE-2018-4113P4MEDIUMCVSS 6.5fixed in 12.7.42018-04-03
CVE-2018-4113 [MEDIUM] CWE-617 CVE-2018-4113: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves a JavaScriptCore function in the "WebKit" component. It allows attackers
nvd
CVE-2016-4760P4MEDIUMCVSS 6.5≤ 12.4.32016-09-25
CVE-2016-4760 [MEDIUM] CWE-284 CVE-2016-4760: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote a WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support.
nvd
CVE-2021-1857P4MEDIUMCVSS 6.5fixed in 12.11.32021-09-08
CVE-2021-1857 [MEDIUM] CWE-665 CVE-2021-1857: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iT A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitiv
nvd
CVE-2017-7153P4MEDIUMCVSS 6.1fixed in 12.7.22018-04-03
CVE-2017-7153 [MEDIUM] CWE-601 CVE-2017-7153: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof user-interf
nvd
Apple Itunes vulnerabilities | cvebase