CVE-2012-0677
high · 9.3Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.
9.3
CVSS
15.4%
EPSS (exploit prob.)
97th
EPSS percentile
2012-06-12
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | itunes | <= 10.6.1 |
| apple | itunes | 10.0 |
| apple | itunes | 10.0.1 |
| apple | itunes | 10.1 |
| apple | itunes | 10.1.1 |
| apple | itunes | 10.1.1.4 |
| apple | itunes | 10.1.2 |
| apple | itunes | 10.2 |
| apple | itunes | 10.2.2.12 |
| apple | itunes | 10.3 |
| apple | itunes | 10.3.1 |
| apple | itunes | 10.4 |
| apple | itunes | 10.4.0.80 |
| apple | itunes | 10.4.1 |
| apple | itunes | 10.4.1.10 |
| apple | itunes | 10.5 |
| apple | itunes | 10.5.1 |
| apple | itunes | 10.5.1.42 |
| apple | itunes | 10.5.2 |
| apple | itunes | 10.5.3 |
| apple | itunes | 10.6 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.apple.com/archives/security-announce/2012/Jun/msg00000.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17016
- http://lists.apple.com/archives/security-announce/2012/Jun/msg00000.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17016
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-0677