cbcvebase.

Apple Itunes vulnerabilities

953 known vulnerabilities affecting apple/itunes.

Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5

Vulnerabilities

Page 47 of 48
CVE-2020-11758P4MEDIUMCVSS 5.5fixed in 12.10.82020-04-14
CVE-2020-11758 [MEDIUM] CWE-125 CVE-2020-11758: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixel An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
nvd
CVE-2020-11761P4MEDIUMCVSS 5.5fixed in 12.10.82020-04-14
CVE-2020-11761 [MEDIUM] CWE-125 CVE-2020-11761: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncom An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
nvd
CVE-2020-13434P4MEDIUMCVSS 5.5fixed in 12.10.92020-05-24
CVE-2020-13434 [MEDIUM] CWE-190 CVE-2020-13434: SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
nvd
CVE-2017-7079P4MEDIUMCVSS 5.5≤ 12.6.22017-10-23
CVE-2017-7079 [MEDIUM] CWE-552 CVE-2017-7079: An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involve An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written by iTunes) via a crafted app.
nvdapple
CVE-2011-3909P4MEDIUMCVSS 5.0fixed in 10.62011-12-13
CVE-2011-3909 [MEDIUM] CWE-119 CVE-2011-3909: The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platfo The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, which allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2024-44157P4MEDIUMCVSS 5.5fixed in 12.13.32024-10-11
CVE-2024-44157 [MEDIUM] CWE-787 CVE-2024-44157: A stack buffer overflow was addressed through improved input validation. This issue is fixed in Appl A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
nvd
CVE-2011-2877P4MEDIUMCVSS 6.8fixed in 10.62011-10-04
CVE-2011-2877 [MEDIUM] CVE-2011-2877: Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers t Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale font."
nvd
CVE-2015-5920P4MEDIUMCVSS 4.3≤ 12.22015-09-18
CVE-2015-5920 [MEDIUM] CVE-2015-5920: The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, whic The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.
nvdapple
CVE-2020-11765P4MEDIUMCVSS 5.5fixed in 12.10.82020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2016-6153P4MEDIUMCVSS 5.9v12.62017-03-21
CVE-2016-6153 [MEDIUM] CVE-2016-6153: iTunes 12.6 Apple Security Update: About the security content of iTunes 12.6 Product: iTunes Version: 12.6 CVE: CVE-2016-6153 Component: CVE-2016-6153 Impact: Multiple issues in expat Description: Multiple issues existed in expat. These issues were addressed by updating expat to version 2.2.0.
apple
CVE-2011-3908P4MEDIUMCVSS 5.0fixed in 10.62011-12-13
CVE-2011-3908 [MEDIUM] CWE-125 CVE-2011-3908: Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attacker Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2018-4440P4MEDIUMCVSS 4.3fixed in 12.9.22019-04-03
CVE-2018-4440 [MEDIUM] CWE-20 CVE-2018-4440: A logic issue was addressed with improved state management. This issue affected versions prior to iO A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2019-8827P4MEDIUMCVSS 4.3fixed in 12.10.22020-10-27
CVE-2019-8827 [MEDIUM] CVE-2019-8827: The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a
nvd
CVE-2019-8898P4MEDIUMCVSS 4.3fixed in 12.10.32020-10-27
CVE-2019-8898 [MEDIUM] CVE-2019-8898: An information disclosure issue existed in the handling of the Storage Access API. This issue was ad An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
nvd
CVE-2009-0016P4MEDIUMCVSS 5.0≤ 8.0v1.0+63 more2009-03-14
CVE-2009-0016 [MEDIUM] CWE-20 CVE-2009-0016: Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite lo Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.
nvd
CVE-2011-3234P4MEDIUMCVSS 5.0fixed in 10.52011-09-19
CVE-2011-3234 [MEDIUM] CWE-125 CVE-2011-3234: Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to c Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2018-4278P4MEDIUMCVSS 4.3fixed in 12.82019-01-11
CVE-2018-4278 [MEDIUM] CVE-2018-4278: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
nvd
CVE-2011-3040P4MEDIUMCVSS 4.3fixed in 10.72012-03-05
CVE-2011-3040 [MEDIUM] CWE-125 CVE-2011-3040: Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cau Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2015-7050P4MEDIUMCVSS 4.3v12.3.2
CVE-2015-7050 [MEDIUM] CVE-2015-7050: iTunes 12.3.2 Apple Security Update: About the security content of iTunes 12.3.2 Product: iTunes Version: 12.3.2 CVE: CVE-2015-7050 Component: CVE-ID
apple
CVE-2005-2938P4HIGHCVSS 7.2v4.7.1.30v5.02005-11-18
CVE-2005-2938 [HIGH] CWE-264 CVE-2005-2938: Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for W Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.
nvd
Apple Itunes vulnerabilities | cvebase