Vulnerabilities > Apple > Itunes > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-26 CVE-2020-7463 Use After Free vulnerability in multiple products
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket.
local
low complexity
freebsd apple CWE-416
5.5
2020-12-08 CVE-2020-27895 Information Exposure vulnerability in Apple Itunes
An information disclosure issue existed in the transition of program state.
network
apple CWE-200
4.3
2020-12-08 CVE-2020-9999 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
A memory corruption issue was addressed with improved state management.
network
apple CWE-119
6.8
2020-12-08 CVE-2020-9947 Use After Free vulnerability in Apple products
A use after free issue was addressed with improved memory management.
network
apple CWE-416
6.8
2020-12-08 CVE-2020-9849 Information Exposure vulnerability in Apple products
An information disclosure issue was addressed with improved state management.
network
low complexity
apple CWE-200
6.5
2020-12-08 CVE-2020-10002 Unspecified vulnerability in Apple products
A logic issue was addressed with improved state management.
local
low complexity
apple
5.5
2020-10-27 CVE-2019-8898 Insecure Storage of Sensitive Information vulnerability in Apple products
An information disclosure issue existed in the handling of the Storage Access API.
network
apple CWE-922
4.3
2020-10-27 CVE-2019-8848 Improper Privilege Management vulnerability in Apple products
This issue was addressed with improved checks.
network
apple CWE-269
6.8
2020-10-27 CVE-2019-8834 Unspecified vulnerability in Apple products
A configuration issue was addressed with additional restrictions.
network
low complexity
apple
4.0
2020-10-27 CVE-2019-8827 Unspecified vulnerability in Apple products
The HTTP referrer header may be used to leak browsing history.
network
apple
4.3