cbcvebase.

Apple Itunes 12.9 For Windows vulnerabilities

25 known vulnerabilities affecting apple/itunes_12.9_for_windows.

Total CVEs
25
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
HIGH23MEDIUM2

Vulnerabilities

Page 2 of 2
CVE-2018-4299HIGHCVSS 8.82018-09-12
CVE-2018-4299 [HIGH] CVE-2018-4299: iTunes 12.9 for Windows Apple Security Update: About the security content of iTunes 12.9 for Windows Product: iTunes 12.9 for Windows CVE: CVE-2018-4299 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4318HIGHCVSS 8.8PoC2018-09-12
CVE-2018-4318 [HIGH] CVE-2018-4318: iTunes 12.9 for Windows Apple Security Update: About the security content of iTunes 12.9 for Windows Product: iTunes 12.9 for Windows CVE: CVE-2018-4318 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management.
apple
CVE-2018-4347HIGHCVSS 7.82018-09-12
CVE-2018-4347 [HIGH] CVE-2018-4347: iTunes 12.9 for Windows Apple Security Update: About the security content of iTunes 12.9 for Windows Product: iTunes 12.9 for Windows CVE: CVE-2018-4347 Component: CoreText Impact: Processing a maliciously crafted text file may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management.
apple
CVE-2018-4309MEDIUMCVSS 6.12018-09-12
CVE-2018-4309 [MEDIUM] CVE-2018-4309: iTunes 12.9 for Windows Apple Security Update: About the security content of iTunes 12.9 for Windows Product: iTunes 12.9 for Windows CVE: CVE-2018-4309 Component: WebKit Impact: A malicious website may be able to execute scripts in the context of another website Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
CVE-2018-4345MEDIUMCVSS 6.12018-09-12
CVE-2018-4345 [MEDIUM] CVE-2018-4345: iTunes 12.9 for Windows Apple Security Update: About the security content of iTunes 12.9 for Windows Product: iTunes 12.9 for Windows CVE: CVE-2018-4345 Component: WebKit Impact: A malicious website may exfiltrate image data cross-origin Description: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
apple
Apple Itunes 12.9 For Windows vulnerabilities | cvebase