CVE-2012-0677: Apple iTunes
High severity, CVSS 9.3. EPSS: 15.4% chance of exploitation in the next 30 days.
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.
Affected products
- Apple iTunes: up to and including 10.6.1; version 10.0 only; version 10.0.1 only; version 10.1 only; version 10.1.1 only; version 10.1.1.4 only; …
Published 2012-06-12. Last modified 2026-06-16.