Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 40 of 48
CVE-2018-4374P4MEDIUMCVSS 6.1fixed in 12.9.12019-04-03
CVE-2018-4374 [MEDIUM] CWE-79 CVE-2018-4374: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1
A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2019-8813P4MEDIUMCVSS 6.1fixed in 12.10.22019-12-18
CVE-2019-8813 [MEDIUM] CWE-79 CVE-2019-8813: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2019-8719P4MEDIUMCVSS 6.1fixed in 12.10.12019-12-18
CVE-2019-8719 [MEDIUM] CWE-79 CVE-2019-8719: A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes f
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2019-8625P4MEDIUMCVSS 6.1fixed in 12.10.12019-12-18
CVE-2019-8625 [MEDIUM] CWE-79 CVE-2019-8625: A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes f
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2019-8762P4MEDIUMCVSS 6.1fixed in 12.10.12020-10-27
CVE-2019-8762 [MEDIUM] CWE-79 CVE-2019-8762: A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1
A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2017-13864P4MEDIUMCVSS 5.9fixed in 12.7.22017-12-25
CVE-2017-13864 [MEDIUM] CWE-200 CVE-2017-13864: An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes
An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attackers to track users by leveraging mishandling of client certificates.
nvd
CVE-2011-1296P4HIGHCVSS 7.5fixed in 10.52011-03-25
CVE-2011-1296 [HIGH] CWE-20 CVE-2011-1296: Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers t
Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1115P4HIGHCVSS 7.5fixed in 10.52011-03-01
CVE-2011-1115 [HIGH] CVE-2011-1115: Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to c
Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1451P4HIGHCVSS 7.5fixed in 10.52011-05-03
CVE-2011-1451 [HIGH] CWE-20 CVE-2011-1451: Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers
Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."
nvd
CVE-2012-3660P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3660 [MEDIUM] CVE-2012-3660: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3673P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3673 [MEDIUM] CVE-2012-3673: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3601P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3601 [MEDIUM] CVE-2012-3601: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3613P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3613 [MEDIUM] CVE-2012-3613: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3602P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3602 [MEDIUM] CVE-2012-3602: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3648P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3648 [MEDIUM] CVE-2012-3648: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3671P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3671 [MEDIUM] CVE-2012-3671: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3614P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3614 [MEDIUM] CVE-2012-3614: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3672P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3672 [MEDIUM] CVE-2012-3672: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3708P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3708 [MEDIUM] CVE-2012-3708: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd
CVE-2012-3677P4MEDIUMCVSS 6.8≤ 10.6.3v4.0.0+76 more2012-09-13
CVE-2012-3677 [MEDIUM] CVE-2012-3677: WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or ca
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
nvd