cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 4 of 48
CVE-2017-13784P2HIGHCVSS 8.8PoCfixed in 12.7.12017-11-13
CVE-2017-13784 [HIGH] CWE-119 CVE-2017-13784: An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of servi
nvd
CVE-2017-13785P2HIGHCVSS 8.8PoCfixed in 12.7.12017-11-13
CVE-2017-13785 [HIGH] CWE-119 CVE-2017-13785: An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of servi
nvd
CVE-2014-8147P3HIGHCVSS 7.5PoCv12.3
CVE-2014-8147 [HIGH] CVE-2014-8147: iTunes 12.3 Apple Security Update: About the security content of iTunes 12.3 Product: iTunes Version: 12.3 CVE: CVE-2014-8147 Component: CVE-ID Impact: Opening a media file may lead to arbitrary code execution Description: A security issue existed in Microsoft Foundation Class's handling of library loading. This issue was addressed by updating to the latest version of the Microsoft Visual C++ Redistributable Package.
apple
CVE-2018-4442P2HIGHCVSS 8.8PoCfixed in 12.9.22019-04-03
CVE-2018-4442 [HIGH] CWE-119 CVE-2018-4442: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2018-4438P2HIGHCVSS 8.8PoCfixed in 12.9.22019-04-03
CVE-2018-4438 [HIGH] CWE-119 CVE-2018-4438: A logic issue existed resulting in memory corruption. This was addressed with improved state managem A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2017-13797P2HIGHCVSS 8.8PoCfixed in 12.7.12017-11-13
CVE-2017-13797 [HIGH] CWE-119 CVE-2017-13797: An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of servi
nvd
CVE-2018-4382P2HIGHCVSS 8.8PoCfixed in 12.9.12019-04-03
CVE-2018-4382 [HIGH] CWE-119 CVE-2018-4382: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2005-0043P3HIGHCVSS 7.5PoCv4.72005-05-02
CVE-2005-0043 [HIGH] CVE-2005-0043: Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
nvd
CVE-2012-0677P3CRITICALCVSS 9.3PoC≤ 10.6.1v10.0+19 more2012-06-12
CVE-2012-0677 [CRITICAL] CWE-119 CVE-2012-0677: Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.
nvd
CVE-2008-4116P3CRITICALCVSS 9.3PoCv8.02008-09-18
CVE-2008-4116 [CRITICAL] CWE-119 CVE-2008-4116: Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that lea
nvd
CVE-2009-2817P3CRITICALCVSS 9.3PoC≤ 9.0v1.0+71 more2009-09-24
CVE-2009-2817 [CRITICAL] CWE-119 CVE-2009-2817: Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or ca Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file.
nvd
CVE-2017-2479P3MEDIUMCVSS 6.5PoCfixed in 12.62017-04-02
CVE-2017-2479 [MEDIUM] CWE-20 CVE-2017-2479: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive inf
nvd
CVE-2017-7089P3MEDIUMCVSS 6.1PoC≤ 12.6.22017-10-23
CVE-2017-7089 [MEDIUM] CWE-79 CVE-2017-7089: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.
nvd
CVE-2008-5406P3CRITICALCVSS 9.3PoCv8.0.2.202008-12-10
CVE-2008-5406 [CRITICAL] CWE-119 CVE-2008-5406: Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attack Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."
nvd
CVE-2017-2480P3MEDIUMCVSS 6.5PoC≤ 12.5.5.52017-04-02
CVE-2017-2480 [MEDIUM] CWE-200 CVE-2017-2480: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive in
nvd
CVE-2019-8600P2CRITICALCVSS 9.8fixed in 12.9.52019-12-18
CVE-2019-8600 [CRITICAL] CWE-89 CVE-2019-8600: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.
nvd
CVE-2019-8649P3MEDIUMCVSS 6.1PoCfixed in 12.9.62019-12-18
CVE-2019-8649 [MEDIUM] CWE-79 CVE-2019-8649: A logic issue existed in the handling of synchronous page loads. This issue was addressed with impro A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross sit
nvd
CVE-2019-8690P3MEDIUMCVSS 6.1PoCfixed in 12.9.62019-12-18
CVE-2019-8690 [MEDIUM] CWE-79 CVE-2019-8690: A logic issue existed in the handling of document loads. This issue was addressed with improved stat A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site script
nvd
CVE-2022-26711P3CRITICALCVSS 9.8fixed in 12.12.42022-05-26
CVE-2022-26711 [CRITICAL] CWE-190 CVE-2022-26711: An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2020-9895P3CRITICALCVSS 9.8fixed in 12.10.82020-10-16
CVE-2020-9895 [CRITICAL] CWE-416 CVE-2020-9895: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
Apple Itunes vulnerabilities | cvebase