SB2012091301 - Multiple vulnerabilities in Apple iTunes



SB2012091301 - Multiple vulnerabilities in Apple iTunes

Published: September 13, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012091301
Severity
Medium
Patch available
YES
Number of vulnerabilities 45
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 45 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2012-3702)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


2) Input validation error (CVE-ID: CVE-2012-3703)

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


3) Input validation error (CVE-ID: CVE-2012-3704)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


4) Input validation error (CVE-ID: CVE-2012-3705)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


5) Input validation error (CVE-ID: CVE-2012-3706)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


6) Input validation error (CVE-ID: CVE-2012-3707)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


7) Input validation error (CVE-ID: CVE-2012-3708)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


8) Input validation error (CVE-ID: CVE-2012-3709)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


9) Input validation error (CVE-ID: CVE-2012-3710)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


10) Input validation error (CVE-ID: CVE-2012-3711)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


11) Input validation error (CVE-ID: CVE-2012-3712)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


12) Input validation error (CVE-ID: CVE-2012-3657)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


13) Input validation error (CVE-ID: CVE-2012-3658)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


14) Input validation error (CVE-ID: CVE-2012-3659)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


15) Input validation error (CVE-ID: CVE-2012-3660)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


16) Input validation error (CVE-ID: CVE-2012-3671)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


17) Input validation error (CVE-ID: CVE-2012-3672)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


18) Input validation error (CVE-ID: CVE-2012-3673)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


19) Input validation error (CVE-ID: CVE-2012-3675)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


20) Input validation error (CVE-ID: CVE-2012-3676)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


21) Input validation error (CVE-ID: CVE-2012-3677)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


22) Input validation error (CVE-ID: CVE-2012-3684)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


23) Input validation error (CVE-ID: CVE-2012-3685)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


24) Input validation error (CVE-ID: CVE-2012-3688)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


25) Input validation error (CVE-ID: CVE-2012-3692)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


26) Input validation error (CVE-ID: CVE-2012-3699)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


27) Input validation error (CVE-ID: CVE-2012-3700)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


28) Input validation error (CVE-ID: CVE-2012-3601)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


29) Input validation error (CVE-ID: CVE-2012-3602)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


30) Input validation error (CVE-ID: CVE-2012-3612)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


31) Input validation error (CVE-ID: CVE-2012-3613)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


32) Input validation error (CVE-ID: CVE-2012-3614)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


33) Input validation error (CVE-ID: CVE-2012-3616)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


34) Input validation error (CVE-ID: CVE-2012-3617)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


35) Input validation error (CVE-ID: CVE-2012-3622)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


36) Input validation error (CVE-ID: CVE-2012-3623)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


37) Input validation error (CVE-ID: CVE-2012-3624)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


38) Input validation error (CVE-ID: CVE-2012-3643)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


39) Input validation error (CVE-ID: CVE-2012-3647)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


40) Input validation error (CVE-ID: CVE-2012-3648)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


41) Input validation error (CVE-ID: CVE-2012-3649)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


42) Input validation error (CVE-ID: CVE-2012-3651)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


43) Input validation error (CVE-ID: CVE-2012-3652)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


44) Input validation error (CVE-ID: CVE-2012-3654)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


45) Input validation error (CVE-ID: CVE-2012-3598)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

WebKit, as used in Apple iTunes before 10.7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-09-12-1.


Remediation

Install update from vendor's website.

References