Vulnerabilities > Apple > Itunes > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-05 CVE-2019-6221 Out-of-bounds Read vulnerability in Apple Iphone OS
An out-of-bounds read was addressed with improved bounds checking.
local
low complexity
apple CWE-125
7.8
2019-03-05 CVE-2019-6217 Out-of-bounds Write vulnerability in Apple products
Multiple memory corruption issues were addressed with improved memory handling.
network
low complexity
apple CWE-787
8.8
2019-03-05 CVE-2019-6216 Out-of-bounds Write vulnerability in Apple products
Multiple memory corruption issues were addressed with improved memory handling.
network
low complexity
apple CWE-787
8.8
2019-03-05 CVE-2019-6215 Type Confusion vulnerability in multiple products
A type confusion issue was addressed with improved memory handling.
network
low complexity
apple canonical CWE-843
8.8
2019-03-05 CVE-2019-6212 Out-of-bounds Write vulnerability in multiple products
Multiple memory corruption issues were addressed with improved memory handling.
network
low complexity
apple canonical CWE-787
8.8
2019-01-11 CVE-2018-4262 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
network
low complexity
apple canonical CWE-119
8.8
2019-01-11 CVE-2018-4213 Improper Input Validation vulnerability in multiple products
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure.
network
low complexity
apple canonical webkitgtk CWE-20
8.8
2019-01-11 CVE-2018-4212 In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure.
network
low complexity
apple canonical webkitgtk
8.8
2019-01-11 CVE-2018-4210 Improper Validation of Array Index vulnerability in multiple products
In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core.
network
low complexity
apple canonical webkitgtk CWE-129
8.8
2019-01-11 CVE-2018-4209 Improper Input Validation vulnerability in multiple products
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure.
network
low complexity
apple canonical webkit CWE-20
8.8