Vulnerabilities > Apple > Itunes > 7.6.2

DATE CVE VULNERABILITY TITLE RISK
2010-08-20 CVE-2010-1768 Local Privilege Escalation vulnerability in Apple iTunes Log File Insecure File Operation
Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.
local
apple
6.9
2010-07-30 CVE-2010-1777 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes
Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted itpc: URL.
network
apple microsoft CWE-119
critical
9.3
2010-06-30 CVE-2010-2249 Memory Leak vulnerability in multiple products
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
6.5
2010-06-30 CVE-2010-1205 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
9.8
2010-06-18 CVE-2010-1769 Multiple vulnerability in RETIRED: Apple iPhone/iPod touch Prior to iOS 4
WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.
network
low complexity
apple microsoft
critical
10.0
2010-06-18 CVE-2010-1763 Unspecified vulnerability in Apple Itunes
Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769.
network
low complexity
apple microsoft
critical
10.0
2010-06-18 CVE-2010-1387 Resource Management Errors vulnerability in Apple Itunes
Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
network
apple CWE-399
critical
9.3
2010-03-31 CVE-2010-0532 Race Condition vulnerability in Apple Itunes
Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.
6.9
2010-03-31 CVE-2010-0531 Resource Management Errors vulnerability in Apple Itunes
Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.
4.3
2009-09-24 CVE-2009-2817 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes
Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file.
network
apple CWE-119
critical
9.3