Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1008

Опубликовано: 20 фев. 2007
Источник: nvd
CVSS2: 2.6
EPSS Низкий

Описание

Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apple:itunes:7.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.09013
Низкий

2.6 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.

EPSS

Процентиль: 92%
0.09013
Низкий

2.6 Low

CVSS2

Дефекты

NVD-CWE-Other