CVE-2010-1387

Description

Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.537

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Apple iTunes (X64) 9.0.3Windows
Multiple vulnerabilities affected in Apple iTunes 9.0.3Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 9.0.3Windows
Multiple Vulnerabilities are affected in Apple iTunes 9.0.3Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 4.7.2Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 7.6Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 7.7Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 9.0.0Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 9.0.1Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 9.0.2Windows
Multiple Vulnerabilities are affected in Apple iTunes 4.7.2Windows
Multiple Vulnerabilities are affected in Apple iTunes 7.6Windows
Multiple Vulnerabilities are affected in Apple iTunes 7.7Windows
Multiple Vulnerabilities are affected in Apple iTunes 9.0.0Windows
Multiple Vulnerabilities are affected in Apple iTunes 9.0.1Windows
Multiple Vulnerabilities are affected in Apple iTunes 9.0.2Windows
Multiple Vulnerabilities are affected in Apple iTunes For Mac 6.0.4.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 4.7.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 7.6Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 7.7Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 8.0.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 8.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 8.1.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 8.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 8.2.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 9.0.0Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 9.0.1Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 9.0.2Mac
Multiple Vulnerabilities are affected in Apple iTunes For Mac 9.0.3Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342817Apple iTunes (X64) (12.13.4.4)
PATCH-342816Apple iTunes (12.13.4.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234