CVE-2011-3252
Buffer overflow in CoreAudio, as used in Apple iTunes before 10.5, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Advanced Audio Coding (AAC) stream.
- Apple Itunes
- ≤ 10.4.1, 4.0.0, 4.0.1, 4.1.0, 4.2.0, 4.5, 4.5.0, 4.6, 4.6.0, 4.7, 4.7.0, 4.7.1, 4.7.2, 4.8.0, 4.9.0, 5.0, 5.0.0, 5.0.1, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.4.2, 6.0.5, 7.0.0, 7.0.1, 7.0.2, 7.1.0, 7.1.1, 7.2.0, 7.3.0, 7.3.1, 7.3.2, 7.4, 7.4.0, 7.4.1, 7.4.2, 7.4.3, 7.5
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 5.6% (92th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2011-10-12
CVE-2011-3252 at NVD
2 known exploits for CVE-2011-3252
Proof-of-concept code and exploit modules indexed by Sploitus