Vulnerabilities > Apple > Itunes > 7.4.3

DATE CVE VULNERABILITY TITLE RISK
2009-03-14 CVE-2009-0016 Improper Input Validation vulnerability in Apple Itunes
Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.
network
low complexity
apple microsoft CWE-20
5.0
2008-09-11 CVE-2008-3636 Numeric Errors vulnerability in Apple Itunes
Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges.
local
low complexity
apple CWE-189
7.2
2008-09-11 CVE-2008-3634 Information Exposure vulnerability in Apple Itunes
Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be absent if the administrator were given better information.
network
high complexity
apple CWE-200
2.6