Sploitus

CVE-2011-0259

1 known exploit for CVE-2011-0259

CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

Affected products
Corefoundation, Itunes
Apple Itunes
≤ 10.4.1, 4.0.0, 4.0.1, 4.1.0, 4.2.0, 4.5, 4.5.0, 4.6, 4.6.0, 4.7, 4.7.0, 4.7.1, 4.7.2, 4.8.0, 4.9.0, 5.0, 5.0.0, 5.0.1, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.4.2, 6.0.5, 7.0.0, 7.0.1, 7.0.2, 7.1.0, 7.1.1, 7.2.0, 7.3.0, 7.3.1, 7.3.2, 7.4, 7.4.0, 7.4.1, 7.4.2, 7.4.3, 7.5
CVSS 2.0
7.6 HIGH
EPSS
2.6% (84th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2011-10-12
CVE-2011-0259 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-0259

Proof-of-concept code and exploit modules indexed by Sploitus