Vulnerabilities > Apple > Itunes > 12.7.4

DATE CVE VULNERABILITY TITLE RISK
2019-03-05 CVE-2019-6215 Type Confusion vulnerability in multiple products
A type confusion issue was addressed with improved memory handling.
6.8
2019-03-05 CVE-2019-6212 Out-of-bounds Write vulnerability in multiple products
Multiple memory corruption issues were addressed with improved memory handling.
6.8
2019-01-11 CVE-2018-4278 In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin.
network
low complexity
apple canonical
4.3
2019-01-11 CVE-2018-4262 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
network
low complexity
apple canonical CWE-119
8.8
2019-01-11 CVE-2018-4194 Out-of-bounds Read vulnerability in Apple products
In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.
6.8
2018-06-08 CVE-2018-4246 Incorrect Type Conversion or Cast vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2018-06-08 CVE-2018-4233 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2018-06-08 CVE-2018-4232 Unspecified vulnerability in Apple products
An issue was discovered in certain Apple products.
4.3
2018-06-08 CVE-2018-4226 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple microsoft CWE-200
2.1
2018-06-08 CVE-2018-4225 Improper Input Validation vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple microsoft CWE-20
2.1