cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 37 of 48
CVE-2015-5930P4MEDIUMCVSS 6.8≤ 12.3.02015-10-23
CVE-2015-5930 [MEDIUM] CWE-119 CVE-2015-5930: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvdapple
CVE-2015-7012P4MEDIUMCVSS 6.8≤ 12.3.02015-10-23
CVE-2015-7012 [MEDIUM] CWE-119 CVE-2015-7012: WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remot WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-20
nvdapple
CVE-2015-7013P4MEDIUMCVSS 6.8≤ 12.3.02015-10-23
CVE-2015-7013 [MEDIUM] CWE-119 CVE-2015-7013: WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to ex WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.
nvdapple
CVE-2015-5931P4MEDIUMCVSS 6.8≤ 12.3.02015-10-23
CVE-2015-5931 [MEDIUM] CWE-119 CVE-2015-5931: WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to ex WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.
nvdapple
CVE-2015-7011P4MEDIUMCVSS 6.8≤ 12.3.02015-10-23
CVE-2015-7011 [MEDIUM] CWE-119 CVE-2015-7011: WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to ex WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.
nvdapple
CVE-2015-1075P4MEDIUMCVSS 6.8≤ 12.12015-03-18
CVE-2015-1075 [MEDIUM] CWE-399 CVE-2015-1075: WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.
nvdapple
CVE-2013-1011P4MEDIUMCVSS 6.8≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1011 [MEDIUM] CWE-399 CVE-2013-1011: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2019-13118P4MEDIUMCVSS 5.3fixed in 12.9.62019-07-01
CVE-2019-13118 [MEDIUM] CWE-843 CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
nvd
CVE-2008-3636P4HIGHCVSS 7.2≤ 7.6.1v1.0+41 more2008-09-11
CVE-2008-3636 [HIGH] CWE-189 CVE-2008-3636: Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple
nvd
CVE-2018-4273P4MEDIUMCVSS 6.5fixed in 12.82019-04-03
CVE-2018-4273 [MEDIUM] CWE-119 CVE-2018-4273: Multiple memory corruption issues were addressed with improved input validation. This issue affected Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4270P4MEDIUMCVSS 6.5fixed in 12.82019-04-03
CVE-2018-4270 [MEDIUM] CWE-119 CVE-2018-4270: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4439P4MEDIUMCVSS 6.5fixed in 12.9.22019-04-03
CVE-2018-4439 [MEDIUM] CWE-20 CVE-2018-4439: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1 A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2020-3861P4HIGHCVSS 7.1fixed in 12.10.42020-02-27
CVE-2020-3861 [HIGH] CVE-2020-3861: The issue was addressed with improved permissions logic. This issue is fixed in iTunes for Windows 1 The issue was addressed with improved permissions logic. This issue is fixed in iTunes for Windows 12.10.4. A user may gain access to protected parts of the file system.
nvd
CVE-2005-1248P4HIGHCVSS 7.5v4.2.72v4.5+3 more2005-05-16
CVE-2005-1248 [HIGH] CVE-2005-1248: Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a c Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.
nvd
CVE-2016-4758P4MEDIUMCVSS 6.5≤ 12.4.32016-09-25
CVE-2016-4758 [MEDIUM] CWE-200 CVE-2016-4758: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not proper WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2018-4444P4MEDIUMCVSS 6.5fixed in 12.9.22020-10-27
CVE-2018-4444 [MEDIUM] CVE-2018-4444: A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iO A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2016-4613P4MEDIUMCVSS 6.5≤ 12.5.12017-02-20
CVE-2016-4613 [MEDIUM] CWE-200 CVE-2016-4613: An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6 An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2011-1121P4HIGHCVSS 7.5fixed in 10.52011-03-01
CVE-2011-1121 [HIGH] CWE-190 CVE-2011-1121: Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of se Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.
nvd
CVE-2011-1188P4HIGHCVSS 7.5fixed in 10.52011-03-11
CVE-2011-1188 [HIGH] CVE-2011-1188: Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attack Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2827P4HIGHCVSS 7.5fixed in 10.52011-08-29
CVE-2011-2827 [HIGH] CWE-416 CVE-2011-2827: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text searching.
nvd
Apple Itunes vulnerabilities | cvebase