VendorsAppleitunes9.0.0
Vulnerabilities

Apple iTunes 9.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

164CVEs
CVE-2012-3676
WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.
Published 2012-09-13 · Modified
6.8EPSS 0.022
CVE-2013-1011
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
Published 2013-05-19 · Modified
6.8EPSS 0.020
CVE-2010-0531
Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.
Published 2010-03-31 · Modified
4.3EPSS 0.019
CVE-2013-1014
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.
Published 2013-05-19 · Modified
4.3EPSS 0.003
← Prev5 / 5