CVE-2014-1242
Apple iTunes < 11.1.4 - Man-in-the-Middle Content Spoofing via HTTP Tutorials Window
Title source: llmDescription
Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/65088
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1029671
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/102410
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6001
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90653
Scores
EPSS
0.0102
EPSS Percentile
59.8%
Details
CWE
CWE-310
Status
published
Products (10)
apple/itunes
11.0
apple/itunes
11.0.1
apple/itunes
11.0.2
apple/itunes
11.0.3
apple/itunes
11.0.4
apple/itunes
11.0.5
apple/itunes
11.1
apple/itunes
11.1.1
apple/itunes
11.1.2
apple/itunes
< 11.1.3
Published
Jan 23, 2014
Tracked Since
Feb 18, 2026