Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 47 of 48
CVE-2020-11758P4MEDIUMCVSS 5.5fixed in 12.10.82020-04-14
CVE-2020-11758 [MEDIUM] CWE-125 CVE-2020-11758: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixel
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.
nvd
CVE-2020-11761P4MEDIUMCVSS 5.5fixed in 12.10.82020-04-14
CVE-2020-11761 [MEDIUM] CWE-125 CVE-2020-11761: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncom
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.
nvd
CVE-2020-13434P4MEDIUMCVSS 5.5fixed in 12.10.92020-05-24
CVE-2020-13434 [MEDIUM] CWE-190 CVE-2020-13434: SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
nvd
CVE-2017-7079P4MEDIUMCVSS 5.5≤ 12.6.22017-10-23
CVE-2017-7079 [MEDIUM] CWE-552 CVE-2017-7079: An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involve
An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written by iTunes) via a crafted app.
nvdapple
CVE-2011-3909P4MEDIUMCVSS 5.0fixed in 10.62011-12-13
CVE-2011-3909 [MEDIUM] CWE-119 CVE-2011-3909: The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platfo
The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, which allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2024-44157P4MEDIUMCVSS 5.5fixed in 12.13.32024-10-11
CVE-2024-44157 [MEDIUM] CWE-787 CVE-2024-44157: A stack buffer overflow was addressed through improved input validation. This issue is fixed in Appl
A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
nvd
CVE-2011-2877P4MEDIUMCVSS 6.8fixed in 10.62011-10-04
CVE-2011-2877 [MEDIUM] CVE-2011-2877: Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers t
Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale font."
nvd
CVE-2015-5920P4MEDIUMCVSS 4.3≤ 12.22015-09-18
CVE-2015-5920 [MEDIUM] CVE-2015-5920: The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, whic
The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.
nvdapple
CVE-2020-11765P4MEDIUMCVSS 5.5fixed in 12.10.82020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2016-6153P4MEDIUMCVSS 5.9v12.62017-03-21
CVE-2016-6153 [MEDIUM] CVE-2016-6153: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2016-6153
Component: CVE-2016-6153
Impact: Multiple issues in expat
Description: Multiple issues existed in expat. These issues were addressed by updating expat to version 2.2.0.
apple
CVE-2011-3908P4MEDIUMCVSS 5.0fixed in 10.62011-12-13
CVE-2011-3908 [MEDIUM] CWE-125 CVE-2011-3908: Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attacker
Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2018-4440P4MEDIUMCVSS 4.3fixed in 12.9.22019-04-03
CVE-2018-4440 [MEDIUM] CWE-20 CVE-2018-4440: A logic issue was addressed with improved state management. This issue affected versions prior to iO
A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2019-8827P4MEDIUMCVSS 4.3fixed in 12.10.22020-10-27
CVE-2019-8827 [MEDIUM] CVE-2019-8827: The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading
The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a
nvd
CVE-2019-8898P4MEDIUMCVSS 4.3fixed in 12.10.32020-10-27
CVE-2019-8898 [MEDIUM] CVE-2019-8898: An information disclosure issue existed in the handling of the Storage Access API. This issue was ad
An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
nvd
CVE-2009-0016P4MEDIUMCVSS 5.0≤ 8.0v1.0+63 more2009-03-14
CVE-2009-0016 [MEDIUM] CWE-20 CVE-2009-0016: Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite lo
Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.
nvd
CVE-2011-3234P4MEDIUMCVSS 5.0fixed in 10.52011-09-19
CVE-2011-3234 [MEDIUM] CWE-125 CVE-2011-3234: Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to c
Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2018-4278P4MEDIUMCVSS 4.3fixed in 12.82019-01-11
CVE-2018-4278 [MEDIUM] CVE-2018-4278: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
nvd
CVE-2011-3040P4MEDIUMCVSS 4.3fixed in 10.72012-03-05
CVE-2011-3040 [MEDIUM] CWE-125 CVE-2011-3040: Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cau
Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2015-7050P4MEDIUMCVSS 4.3v12.3.2
CVE-2015-7050 [MEDIUM] CVE-2015-7050: iTunes 12.3.2
Apple Security Update: About the security content of iTunes 12.3.2
Product: iTunes
Version: 12.3.2
CVE: CVE-2015-7050
Component: CVE-ID
apple
CVE-2005-2938P4HIGHCVSS 7.2v4.7.1.30v5.02005-11-18
CVE-2005-2938 [HIGH] CWE-264 CVE-2005-2938: Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for W
Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.
nvd