VendorsAppleitunes11.0.1
Vulnerabilities

Apple iTunes 11.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2013-1035
The iTunes ActiveX control in Apple iTunes before 11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Published 2013-09-19 · Modified
9.3EPSS 0.041
CVE-2014-1242
Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.
Published 2014-01-23 · Modified
5.8EPSS 0.010
CVE-2014-1347
Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.
Published 2014-05-18 · Modified
4.4EPSS 0.004