Vulnerabilities > Apple > Itunes > 4.5

DATE CVE VULNERABILITY TITLE RISK
2007-09-06 CVE-2007-3752 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes
Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.
network
apple CWE-119
critical
9.3
2006-06-29 CVE-2006-1467 Numeric Errors vulnerability in Apple Itunes
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.
network
high complexity
apple CWE-189
5.1
2005-05-16 CVE-2005-1248 Buffer Overflow vulnerability in Apple iTunes MPEG4 Parsing
Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.
network
low complexity
apple
7.5