Vulnerabilities > Apple > Itunes

DATE CVE VULNERABILITY TITLE RISK
2008-09-11 CVE-2008-3634 Information Exposure vulnerability in Apple Itunes
Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be absent if the administrator were given better information.
network
high complexity
apple CWE-200
2.6
2008-08-01 CVE-2008-3434 Code Injection vulnerability in Apple Itunes
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
network
low complexity
apple CWE-94
7.5
2007-09-06 CVE-2007-3752 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes
Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.
network
apple CWE-119
critical
9.3
2007-02-20 CVE-2007-1008 Remote Denial of Service vulnerability in Apple Itunes 7.0.2
Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption.
network
high complexity
apple
2.6
2006-06-29 CVE-2006-1467 Numeric Errors vulnerability in Apple Itunes
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.
network
high complexity
apple CWE-189
5.1
2006-03-19 CVE-2006-1249 Numeric Errors vulnerability in Apple Itunes and Quicktime
Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.
network
apple CWE-189
6.8
2005-12-08 CVE-2005-4092 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes and Quicktime
Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and possibly other vectors involving media files.
network
low complexity
apple CWE-119
7.5
2005-11-18 CVE-2005-2938 Permissions, Privileges, and Access Controls vulnerability in Apple Itunes 4.7.1.30/5.0
Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.
local
low complexity
apple CWE-264
7.2
2005-05-16 CVE-2005-1248 Buffer Overflow vulnerability in Apple iTunes MPEG4 Parsing
Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.
network
low complexity
apple
7.5
2005-05-02 CVE-2005-0043 Buffer Overflow vulnerability in Apple Itunes 4.7
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
network
low complexity
apple
7.5