Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 39 of 48
CVE-2020-3867P4MEDIUMCVSS 6.1fixed in 12.10.42020-02-27
CVE-2020-3867 [MEDIUM] CWE-79 CVE-2020-3867: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iP
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2021-1825P4MEDIUMCVSS 6.1fixed in 12.11.32021-09-08
CVE-2021-1825 [MEDIUM] CWE-79 CVE-2021-1825: An input validation issue was addressed with improved input validation. This issue is fixed in iTune
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2018-4266P4MEDIUMCVSS 5.9fixed in 12.82019-04-03
CVE-2018-4266 [MEDIUM] CWE-362 CVE-2018-4266: A race condition was addressed with additional validation. This issue affected versions prior toiVer
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2019-8658P4MEDIUMCVSS 6.1fixed in 12.9.62019-12-18
CVE-2019-8658 [MEDIUM] CWE-79 CVE-2019-8658: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2020-9925P4MEDIUMCVSS 6.1fixed in 12.10.82020-10-16
CVE-2020-9925 [MEDIUM] CWE-79 CVE-2020-9925: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2011-0983P4HIGHCVSS 7.5fixed in 10.52011-02-10
CVE-2011-0983 [HIGH] CWE-20 CVE-2011-0983: Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attac
Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-0981P4HIGHCVSS 7.5fixed in 10.52011-02-10
CVE-2011-0981 [HIGH] CWE-20 CVE-2011-0981: Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allow
Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2020-9916P4MEDIUMCVSS 5.3fixed in 12.10.82020-10-16
CVE-2020-9916 [MEDIUM] CVE-2020-9916: A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iO
A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.
nvd
CVE-2011-1203P4HIGHCVSS 7.5fixed in 10.52011-03-11
CVE-2011-1203 [HIGH] CVE-2011-1203: Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attacker
Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1109P4HIGHCVSS 7.5fixed in 10.52011-03-01
CVE-2011-1109 [HIGH] CWE-20 CVE-2011-1109: Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) sty
Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2012-3647P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3647 [MEDIUM] CVE-2012-3647: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2013-1041P4MEDIUMCVSS 6.8≤ 11.1.32013-09-19
CVE-2013-1041 [MEDIUM] CWE-119 CVE-2013-1041: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1047P4MEDIUMCVSS 6.8≤ 11.1.32013-09-19
CVE-2013-1047 [MEDIUM] CWE-119 CVE-2013-1047: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1039P4MEDIUMCVSS 6.8≤ 11.1.32013-09-19
CVE-2013-1039 [MEDIUM] CWE-119 CVE-2013-1039: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1037P4MEDIUMCVSS 6.8≤ 11.1.32013-09-19
CVE-2013-1037 [MEDIUM] CWE-119 CVE-2013-1037: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1040P4MEDIUMCVSS 6.8≤ 11.1.32013-09-19
CVE-2013-1040 [MEDIUM] CWE-119 CVE-2013-1040: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1038P4MEDIUMCVSS 6.8≤ 11.1.32013-09-19
CVE-2013-1038 [MEDIUM] CWE-119 CVE-2013-1038: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2011-3071P4MEDIUMCVSS 6.8fixed in 10.72012-04-05
CVE-2011-3071 [MEDIUM] CWE-416 CVE-2011-3071: Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.102
Use-after-free vulnerability in the HTMLMediaElement implementation in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2020-36521P4HIGHCVSS 7.1fixed in 12.10.92022-09-23
CVE-2020-36521 [HIGH] CWE-125 CVE-2020-36521: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud fo
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2018-4146P4MEDIUMCVSS 6.5fixed in 12.7.42018-04-03
CVE-2018-4146 [MEDIUM] CWE-119 CVE-2018-4146: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows attackers to cause a denial of service
nvd