Itunes

Vendor:

First CVE: May 2, 2005 · Active for 21 years

922
Total CVEs
More Total CVEs than 100% of tracked products
46.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.2%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Itunes over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Oct 11, 2024
651 days ago

CVE Severity & Scoring

Itunes922 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local91 (9.9%)
Network384 (41.6%)
Unknown447 (48.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low466 (50.5%)
High9 (1.0%)
Unknown447 (48.5%)
User Interaction
None54 (5.9%)
Unknown447 (48.5%)
Required421 (45.7%)
Privileges Required
Low21 (2.3%)
High0 (0.0%)
None454 (49.2%)
Unknown447 (48.5%)

Top CVEs

Signals from CVEs in this product scope (922 CVEs).

922 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iClo
Jun 9, 20209.882NOYES
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Wind
Dec 18, 20198.882YESYES
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on
Jun 8, 20188.876NOYES
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
May 2, 20057.575NOYES
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG
Jun 30, 20109.867NOYES
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 Hig
Dec 8, 20207.866YESNO
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a lo
Jun 2, 20099.360NOYES
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Wi
Apr 3, 20188.859NOYES
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1
Apr 3, 20198.858NOYES
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playl
Jun 12, 20129.347NOYES

Exploit Exposure

Signals from CVEs in this product scope (922 CVEs).

CISA KEV
2 CVEs
0.2% of CVEs· 96th percentile
Metasploit
5 CVEs
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
73 CVEs
7.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (922 CVEs).

Media Mentions

Signals from CVEs in this product scope (922 CVEs).

Top CNAs Publishing CVEs For Itunes

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.2.11567.52.8%00
9.21567.52.8%00
9.1.11017.52.7%00
9.11037.52.7%00
9.0.31607.62.8%00
9.0.21647.62.8%00
9.0.11647.62.8%00
9.0.01647.62.8%00
9.047.12.7%00
8.2.1637.93.2%01
8.2637.93.2%01
8.1.1637.93.2%01
8.1648.04.0%02
8.0.2.2029.37.4%01
8.0.2648.04.0%02
8.0.11647.53.2%02
8.0.01637.53.2%02
8.069.413.8%03
7.7.11667.53.2%02
7.7.01657.53.2%02