← All CVEs

CVE-2012-0677

high · 9.3

Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.

9.3
CVSS
15.4%
EPSS (exploit prob.)
97th
EPSS percentile
2012-06-12
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
appleitunes<= 10.6.1
appleitunes10.0
appleitunes10.0.1
appleitunes10.1
appleitunes10.1.1
appleitunes10.1.1.4
appleitunes10.1.2
appleitunes10.2
appleitunes10.2.2.12
appleitunes10.3
appleitunes10.3.1
appleitunes10.4
appleitunes10.4.0.80
appleitunes10.4.1
appleitunes10.4.1.10
appleitunes10.5
appleitunes10.5.1
appleitunes10.5.1.42
appleitunes10.5.2
appleitunes10.5.3
appleitunes10.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-0677