AirKeyboard iOS App 1.0.5 – Remote Input Injection
# Exploit Title: AirKeyboard iOS App 1.0.5 - Remote Input Injection
ios 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: AirKeyboard iOS App 1.0.5 - Remote Input Injection
# Exploit Title: Owlfiles File Manager 12.0.1 - Multiple Vulnerabilities
# Exploit Title: Wifi HD Wireless Disk Drive 11 - Local File Inclusion
# Exploit Title: Notex the best notes 6.4 - Denial of Service (PoC)
# Exploit Title: Post-it 5.0.1 - Denial of Service (PoC)
# Exploit Title: Secure Notepad Private Notes 3.0.3 - Denial of Service (PoC)
# Exploit Title: n+otes 1.6.2 - Denial of Service (PoC)
# Exploit Title: Sticky Notes Widget Version 3.0.6 - Denial of Service (PoC)
# Exploit Title: memono Notepad Version 4.2 - Denial of Service (PoC)
# Exploit Title: Sticky Notes & Color Widgets 1.4.2 - Denial of Service (PoC)
# Exploit Title: My Notes Safe 5.3 - Denial of Service (PoC)
# Exploit Title: Macaron Notes great notebook 5.5 - Denial of Service (PoC)
# Exploit Title: Color Notes 1.4 - Denial of Service (PoC)
# Exploit Title: WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service (PoC)
# Exploit Title: Mini Mouse 9.3.0 - Local File inclusion / Path Traversal
# Title: HardDrive 2.1 for iOS - Arbitrary File Upload
# Title: Super Backup 2.0.5 for iOS - Directory Traversal
# Title: Easy Transfer 1.7 for iOS - Directory Traversal
# Title: Sky File 2.1.0 iOS - Directory Traversal
# Title: Playable 9.18 iOS - Persistent Cross-Site Scripting
# Title: File Transfer iFamily 2.1 - Directory Traversal
# Title: SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
# Title: AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
# Exploit Title: ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
# Exploit Title: P2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of Service (PoC)
# Exploit Title: GHIA CamIP 1.2 for iOS - 'Password' Denial of Service (PoC)
# Exploit Title: iNetTools for iOS 8.20 - 'Whois' Denial of Service (PoC)
mediaserverd has various media parsing responsibilities; its reachable from various sandboxes
# Exploit Title: scadaApp for iOS 1.1.4.0 - 'Servername' Denial of Service (PoC)
# Exploit Title: Open Proficy HMI-SCADA 5.0.0.25920 - 'Password' Denial of Service (PoC)
# Exploit Title: iOS IOUSBDeviceFamily 12.4.1 - 'IOInterruptEventSource' Heap Corruption (PoC)
When an NSKeyedUnarchiver decodes an object, it first allocates the object using allocWithZone, and then puts the obj...
Exploit Title: SockPuppet 3
Visual Voicemail (VVM) is a feature of mobile devices that allows voicemail to be read in an email-like format. Carri...
// (c) 2019 ZecOps, Inc. - https://www.zecops.com - Find Attackers' Mistakes
There is a memory corruption issue when processing a malformed RTP video stream in FaceTime that leads to a kernel pa...
There was recently some cleanup in the persona code to fix some race conditions there, I don't think it was sufficient:
Here's a code snippet from sleh.c with the second level exception handler for undefined instruction exceptions:
# Exploit Title: Trend Micro Virtual Mobile Infrastructure 5.5.1336 - 'Server address' Denial of Service (PoC)
# Exploit Title: Symantec Mobile Encryption for iPhone 2.1.0 - 'Server' Denial of Service (PoC)
# Exploit Title: Cisco AnyConnect Secure Mobility Client 4.6.01099 - 'Introducir URL' Denial of Service (PoC)
# Exploit Title: Trend Micro Enterprise Mobile Security 2.0.0.1700 - 'Servidor' Denial of Service (PoC)
#!/usr/bin/env python
Document Title:
# Exploit Title: TpwnT - iOS Denail of Service POC
#!/usr/bin/env python
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1317#c3
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1289
Sources: