NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3315 | CVE-2008-3434 | Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | 2 | 7.5 | High | 2017-01-03 | 2013-11-02 | View | |
37280 | CVE-2013-1014 | Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | 2 | 4.3 | Medium | 2017-01-18 | 2013-11-02 | View | |
29923 | CVE-2014-1242 | Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream. | 2 | 5.8 | Medium | 2017-01-19 | 2014-01-30 | View | |
30023 | CVE-2014-1347 | Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations. | 2 | 4.4 | Medium | 2017-01-19 | 2014-05-19 | View | |
3502 | CVE-2008-3634 | Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be absent if the administrator were given better information. | 2 | 2.6 | Low | 2017-01-03 | 2008-09-11 | View |
Page 1317 of 17672, showing 5 records out of 88360 total, starting on record 6581, ending on 6585