← Vulnerability feed

Vulnerability record · CVE-2005-0043 · published 2 May 2005

CVE-2005-0043: Apple iTunes playlist URL buffer overflow allows remote code execution

Apple · Itunes

Apple iTunes 4.7 contains a buffer overflow triggered by an overly long URL inside .m3u or .pls playlist files. Because playlists are commonly opened from untrusted sources, a crafted file can crash the application or run attacker-supplied code in the context of the user.

7.5 CVSS 2.0 High EPSS 69% · top 0.7%
7.5CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with no authentication and a high EPSS score, though exploitation depends on the user opening a malicious playlist.

What it is

Apple iTunes 4.7 contains a buffer overflow triggered by an overly long URL inside .m3u or .pls playlist files. Because playlists are commonly opened from untrusted sources, a crafted file can crash the application or run attacker-supplied code in the context of the user.

Impact

An attacker can execute arbitrary code with the privileges of the user running iTunes, potentially leading to full compromise of the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

The flaw is network-reachable (AV:N) with low complexity and no authentication (AC:L/Au:N), but it requires the victim to open or load a malicious playlist file, so user interaction is effectively needed. No affected version range beyond iTunes 4.7 is stated in the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is high (0.69005, 99.3rd percentile) and one reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.

What to do

  • Upgrade iTunes to a version later than 4.7 using the Apple security update referenced in the advisory.
  • Block or filter .m3u and .pls files arriving via email, web downloads or removable media until patching is complete.
  • Configure mail and web gateways to strip or quarantine playlist attachments from untrusted senders.
  • Educate users not to open playlist files from unknown or unexpected sources.
  • Where possible, run iTunes with least privilege to limit the impact of successful exploitation.

Detection

  • Monitor for iTunes crashes or abnormal process terminations when opening .m3u or .pls files.
  • Inspect playlist files for unusually long URL fields or embedded shellcode patterns before they are opened.
  • Alert on iTunes spawning child processes such as cmd.exe or /bin/sh, which would indicate code execution.
  • Review endpoint logs for suspicious file writes or network connections originating from the iTunes process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0043 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-8506Apple WebKit type confusion allows code executionA type confusion flaw in Apple's web rendering components was fixed through improved memory handling. Processing maliciously crafted web content can …KEVEPSS 16%analysed7.8CVE-2020-27932Apple XNU kernel type confusion allows kernel code executionA type confusion flaw in Apple's XNU kernel was fixed through improved state handling across macOS, iOS, iPadOS, watchOS, iCloud and iTunes. A malici…KEVEPSS 10%analysed10.0CVE-2019-6235Apple itunes out-of-bounds write vulnerabilityA memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3…EPSS 2.1%10.0CVE-2010-1763Apple itunes vulnerabilityUnspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2…EPSS 2.7%10.0CVE-2010-1769Apple itunes vulnerabilityWebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling …EPSS 6.9%9.8CVE-2022-26711Apple itunes integer overflow vulnerabilityAn integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iP…EPSS 3.8%9.8CVE-2019-8746Apple icloud out-of-bounds read vulnerabilityAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCl…EPSS 3.0%9.8CVE-2019-8749Apple icloud out-of-bounds write vulnerabilityMultiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Wind…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2005-0043), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.