Apple Itunes vulnerabilities
953 known vulnerabilities affecting apple/itunes.
Total CVEs
953
CISA KEV
2
actively exploited
Public exploits
78
Exploited in wild
10
Severity breakdown
CRITICAL113HIGH487MEDIUM348LOW5
Vulnerabilities
Page 48 of 48
CVE-2010-0532P4MEDIUMCVSS 6.9≤ 9.0.3v9.0+3 more2010-03-31
CVE-2010-0532 [MEDIUM] CWE-362 CVE-2010-0532: Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users
Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.
nvd
CVE-2011-3968P4MEDIUMCVSS 4.3fixed in 10.72012-02-09
CVE-2011-3968 [MEDIUM] CWE-416 CVE-2011-3968: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.
nvd
CVE-2013-1014P4MEDIUMCVSS 4.3≤ 11.0.2v4.0.0+77 more2013-05-20
CVE-2013-1014 [MEDIUM] CWE-20 CVE-2013-1014: Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-midd
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
nvd
CVE-2012-1147P4MEDIUMCVSS 4.3v12.62017-03-21
CVE-2012-1147 [MEDIUM] CVE-2012-1147: iTunes 12.6
Apple Security Update: About the security content of iTunes 12.6
Product: iTunes
Version: 12.6
CVE: CVE-2012-1147
Component: CVE-2012-1147
apple
CVE-2010-1768P4MEDIUMCVSS 6.9≤ 9.0.3v1.0+58 more2010-08-20
CVE-2010-1768 [MEDIUM] CVE-2010-1768: Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges v
Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.
nvd
CVE-2014-1347P4MEDIUMCVSS 4.4≤ 11.2v11.0+11 more2014-05-18
CVE-2014-1347 [MEDIUM] CWE-264 CVE-2014-1347: Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared duri
Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.
nvd
CVE-2010-0531P4MEDIUMCVSS 4.3≤ 9.0.3v9.0+3 more2010-03-31
CVE-2010-0531 [MEDIUM] CWE-399 CVE-2010-0531: Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a c
Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in 10.22010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2011-3027P4MEDIUMCVSS 4.3fixed in 10.72012-02-16
CVE-2011-3027 [MEDIUM] CWE-704 CVE-2011-3027: Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during
Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2020-3894P4LOWCVSS 3.1fixed in 12.10.52020-04-01
CVE-2020-3894 [LOW] CWE-362 CVE-2020-3894: A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadO
A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
nvd
CVE-2008-3634P4LOWCVSS 2.6≤ 7.7.1v1.0+42 more2008-09-11
CVE-2008-3634 [LOW] CWE-200 CVE-2008-3634: Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the
Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be absent if the administrator were given better information.
nvd
CVE-2017-2383P4LOWCVSS 3.1≤ 12.5.5.52017-04-02
CVE-2017-2383 [LOW] CVE-2017-2383: An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes
An issue was discovered in certain Apple products. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. The issue involves cleartext client-certificate transmission in the "APNs Server" component. It allows man-in-the-middle attackers to track users via correlation with this certificate.
nvd
CVE-2020-27895P4LOWCVSS 3.3fixed in 12.112020-12-08
CVE-2020-27895 [LOW] CVE-2020-27895: An information disclosure issue existed in the transition of program state. This issue was addressed
An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious application may be able to access local users Apple IDs.
nvd
← Previous48 / 48