NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3315  CVE-2008-3434  Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.    7.5  High  2017-01-03  2013-11-02  View
37280  CVE-2013-1014  Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.    4.3  Medium  2017-01-18  2013-11-02  View
29923  CVE-2014-1242  Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.    5.8  Medium  2017-01-19  2014-01-30  View
30023  CVE-2014-1347  Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.    4.4  Medium  2017-01-19  2014-05-19  View
3502  CVE-2008-3634  Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be absent if the administrator were given better information.    2.6  Low  2017-01-03  2008-09-11  View

Page 1317 of 17672, showing 5 records out of 88360 total, starting on record 6581, ending on 6585

Actions