Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Itunes | Apple | * | 11.1.3 (including) |
| Itunes | Apple | 11.0 (including) | 11.0 (including) |
| Itunes | Apple | 11.0.1 (including) | 11.0.1 (including) |
| Itunes | Apple | 11.0.2 (including) | 11.0.2 (including) |
| Itunes | Apple | 11.0.3 (including) | 11.0.3 (including) |
| Itunes | Apple | 11.0.4 (including) | 11.0.4 (including) |
| Itunes | Apple | 11.0.5 (including) | 11.0.5 (including) |
| Itunes | Apple | 11.1 (including) | 11.1 (including) |
| Itunes | Apple | 11.1.1 (including) | 11.1.1 (including) |
| Itunes | Apple | 11.1.2 (including) | 11.1.2 (including) |