Lucene search

K
cve[email protected]CVE-2011-0259
HistoryOct 12, 2011 - 6:55 p.m.

CVE-2011-0259

2011-10-1218:55:01
CWE-119
web.nvd.nist.gov
33
corefoundation
apple itunes
cve-2011-0259
man-in-the-middle attack
arbitrary code execution
denial of service
memory corruption
application crash
nvd

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

8.7 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.6%

CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

Affected configurations

NVD
Node
appleitunesRangeโ‰ค10.4.1
OR
appleitunesMatch4.0.0
OR
appleitunesMatch4.0.1
OR
appleitunesMatch4.1.0
OR
appleitunesMatch4.2.0
OR
appleitunesMatch4.5
OR
appleitunesMatch4.5.0
OR
appleitunesMatch4.6
OR
appleitunesMatch4.6.0
OR
appleitunesMatch4.7
OR
appleitunesMatch4.7.0
OR
appleitunesMatch4.7.1
OR
appleitunesMatch4.7.2
OR
appleitunesMatch4.8.0
OR
appleitunesMatch4.9.0
OR
appleitunesMatch5.0
OR
appleitunesMatch5.0.0
OR
appleitunesMatch5.0.1
OR
appleitunesMatch6.0.0
OR
appleitunesMatch6.0.1
OR
appleitunesMatch6.0.2
OR
appleitunesMatch6.0.3
OR
appleitunesMatch6.0.4
OR
appleitunesMatch6.0.4.2
OR
appleitunesMatch6.0.5
OR
appleitunesMatch7.0.0
OR
appleitunesMatch7.0.1
OR
appleitunesMatch7.0.2
OR
appleitunesMatch7.1.0
OR
appleitunesMatch7.1.1
OR
appleitunesMatch7.2.0
OR
appleitunesMatch7.3.0
OR
appleitunesMatch7.3.1
OR
appleitunesMatch7.3.2
OR
appleitunesMatch7.4
OR
appleitunesMatch7.4.0
OR
appleitunesMatch7.4.1
OR
appleitunesMatch7.4.2
OR
appleitunesMatch7.4.3
OR
appleitunesMatch7.5
OR
appleitunesMatch7.5.0
OR
appleitunesMatch7.6
OR
appleitunesMatch7.6.0
OR
appleitunesMatch7.6.1
OR
appleitunesMatch7.6.2
OR
appleitunesMatch7.7
OR
appleitunesMatch7.7.0
OR
appleitunesMatch7.7.1
OR
appleitunesMatch8.0.0
OR
appleitunesMatch8.0.1
OR
appleitunesMatch8.0.2
OR
appleitunesMatch8.1
OR
appleitunesMatch8.1.1
OR
appleitunesMatch8.2
OR
appleitunesMatch8.2.1
OR
appleitunesMatch9.0.0
OR
appleitunesMatch9.0.1
OR
appleitunesMatch9.0.2
OR
appleitunesMatch9.0.3
OR
appleitunesMatch9.2
OR
appleitunesMatch9.2.1
OR
appleitunesMatch10.0
OR
appleitunesMatch10.0.1
OR
appleitunesMatch10.1
OR
appleitunesMatch10.1.1
OR
appleitunesMatch10.1.2
OR
appleitunesMatch10.2
OR
appleitunesMatch10.3
OR
appleitunesMatch10.3.1
OR
appleitunesMatch10.4
AND
microsoftwindows_7
OR
microsoftwindows_vista
OR
microsoftwindows_vistasp1
OR
microsoftwindows_vistasp2
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp3

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

8.7 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.6%