Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfqj-x8w6-93mr

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.

Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.

EPSS

Процентиль: 92%
0.09013
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.

EPSS

Процентиль: 92%
0.09013
Низкий