← back
CVE-2009-0950

CVE-2009-0950

43Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 29%
from disclosure to weapon226 days
Published on NVDJun 2
1st PoC+226d
metasploitJun 1
exploitation probability
29%top 2% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.