CVE-2008-3434

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
appleitunes
𝑥
≤ 6.0.5
appleitunes
1.0
appleitunes
1.1
appleitunes
1.1.1
appleitunes
1.1.2
appleitunes
2.0
appleitunes
2.0.1
appleitunes
2.0.2
appleitunes
2.0.3
appleitunes
2.0.4
appleitunes
3.0
appleitunes
3.0.1
appleitunes
4.0
appleitunes
4.0.1
appleitunes
4.1
appleitunes
4.2
appleitunes
4.5
appleitunes
4.6
appleitunes
4.7
appleitunes
4.7.1
appleitunes
4.8
appleitunes
4.9
appleitunes
5.0
appleitunes
5.0.1
appleitunes
6.0
appleitunes
6.0.1
appleitunes
6.0.2
appleitunes
6.0.3
appleitunes
6.0.4
appleitunes
6.0.4.2
𝑥
= Vulnerable software versions