← Back

Itunes

itunes

Vendor: Apple • 922 CVEs

CVEs (922)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apple
GoogleOpensuse
5Chrome
Iphone OsItunes+2 more
Apr 29, 2026
Mar 5, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG document.
3Apple
GoogleOpensuse
5Chrome
Iphone OsItunes+2 more
Apr 29, 2026
Mar 5, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG values.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 16, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact vi...Show more
Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 16, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to subframe loading.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 16, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-afte...Show more
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token seq...Show more
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sh...Show more
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sheets (CSS) token-sequence data.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Feb 9, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a c...Show more
Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Jan 24, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Jan 24, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM selections.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Dec 13, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to Range handling.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Dec 13, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, which allows remote attackers to cause a denial of service (memory corrupt...Show more
The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, which allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Dec 13, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in...Show more
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Oct 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) t...Show more
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.Show less
1Apple
1Itunes
Apr 29, 2026
Oct 12, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in CoreAudio, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Advanced Audio Coding (AAC) stream.
1Apple
2Itunes
Webkit
Apr 29, 2026
Oct 12, 2011
N/A· v4
N/A· v3
7.6 HIGH· v2
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsin...Show more
WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.Show less