← Back

CVE-2007-1008

nvd nist
Published: Feb 20, 2007Modified: Apr 23, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:N/A:P
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.

Affected (1)

Products: Apple: Itunes
1 product
Itunes
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0.2

References (10)

Timeline

No history available yet.