CVE-2014-1242

Apple iTunes < 11.1.4 - Man-in-the-Middle Content Spoofing via HTTP Tutorials Window

Title source: llm
STIX 2.1

Description

Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65088
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029671
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/102410
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6001
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90653

Scores

EPSS 0.0102
EPSS Percentile 59.8%

Details

CWE
CWE-310
Status published
Products (10)
apple/itunes 11.0
apple/itunes 11.0.1
apple/itunes 11.0.2
apple/itunes 11.0.3
apple/itunes 11.0.4
apple/itunes 11.0.5
apple/itunes 11.1
apple/itunes 11.1.1
apple/itunes 11.1.2
apple/itunes < 11.1.3
Published Jan 23, 2014
Tracked Since Feb 18, 2026