Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

CVE-2009-0016
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 5/10
- Exploit Score
- 10/10
- Access Vector
- Network
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 2.9/10
- Confidentiality Impact
- None
- Availability Impact
- Partial
- Integrity Impact
- None
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:apple:itunes:*:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:1.0:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:1.1.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:1.1.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:2.0:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:2.0.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:2.0.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:2.0.3:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:2.0.4:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:3.0:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:3.0.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.0:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.0.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.0.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.0.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.1.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.2.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.2.72:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.5:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.5.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.6:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.6.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.7:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.7.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.7.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.7.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.7.1.30:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.8:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.8.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.9:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:4.9.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:5.0:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:5.0.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:5.0.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:5.0.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.2:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.3:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.3:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.4:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.4:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.4.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.5:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:6.0.5:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.0.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.0.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.0.2:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.0.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.1.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.1.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.2.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.3.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.3.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.3.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.3.2:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.4:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.4.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.4.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.4.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.4.2:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.4.2:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.4.3:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.5:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.5.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.6:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.6.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.6.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.6.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.6.2:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.7:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.7.0:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.7.1:-:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:apple:itunes:7.7.1:*:windows:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* |
No
|
- |
References
- http://www.securityfocus.com/bid/34094
- http://support.apple.com/kb/HT3487
- http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html
- http://securitytracker.com/id?1021842
- http://secunia.com/advisories/34254
- http://www.fortiguardcenter.com/advisory/FGA-2009-11.html
- http://www.vupen.com/english/advisories/2009/0702
- http://osvdb.org/52578
- http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0236.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49200
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6
- http://www.securityfocus.com/archive/1/501758/100/0/threaded