VulnerabilityModified
CVE-2010-1768
Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.
MEDIUM 6.9EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- apple/itunes
- Source
- product-security@apple.com
References
- http://support.apple.com/kb/HT4105Vendor Advisory
- http://www.securityfocus.com/bid/42538
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61222
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7604
- http://support.apple.com/kb/HT4105Vendor Advisory
- http://www.securityfocus.com/bid/42538
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61222
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7604
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.