Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2021-30862

EPSS 2.22% · P85
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-30862

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apple iTunes 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apple iTunes是美国苹果(Apple)公司的一套媒体播放器应用程序,它主要用于对数字音乐和视频文件进行播放以及管理。 Apple iTunes U 3.8.3之前版本存在输入验证错误漏洞,攻击者可能通过恶意生成的URL导致任意javascript代码的执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
AppleiTunes U unspecified ~ 3.8 -

II. Public POCs for CVE-2021-30862

#POC DescriptionSource LinkShenlong Link
1Write-up and proof of concepts for CVE-2021-30862https://github.com/Umarovm/CVE-2021-30862POC Details
2Write-up and proof of concepts for my vulnerability CVE-2021-30862, 1-click RCE bug in iOS iTunes Uhttps://github.com/3h6-1/CVE-2021-30862POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-30862

登录查看更多情报信息。

Vendor Advisories for CVE-2021-30862 (1)

Same Patch Batch · Apple · 2021-08-24 · 152 CVEs total

CVE-2021-30951Apple iOS 和 iPadOS 资源管理错误漏洞
CVE-2021-30969Apple macOS Big Sur 输入验证错误漏洞
CVE-2021-30968Apple iOS和Apple iPadOS 后置链接漏洞
CVE-2021-30967Apple iOS 和 iPadOS 权限许可和访问控制问题漏洞
CVE-2021-30966Apple iOS 和 iPadOS 信息泄露漏洞
CVE-2021-30965Apple macOS Big Sur 安全漏洞
CVE-2021-30964Apple iOS 和 iPadOS 安全漏洞
CVE-2021-30963Apple macOS Big Sur 缓冲区错误漏洞
CVE-2021-30962Apple tvOS和Apple macOS Big Sur 安全漏洞
CVE-2021-30961Apple macOS Big Sur 缓冲区错误漏洞
CVE-2021-30960Apple iOS 和 iPadOS 缓冲区错误漏洞
CVE-2021-30959Apple macOS Big Sur 缓冲区错误漏洞
CVE-2021-30958Apple iOS 和 iPadOS 缓冲区错误漏洞
CVE-2021-30957Apple iOS 和 iPadOS 缓冲区错误漏洞
CVE-2021-30956Apple iOS和Apple iPadOS 安全漏洞
CVE-2021-30955Apple iOS 和 iPadOS 竞争条件问题漏洞
CVE-2021-30954Apple tvOS 安全漏洞
CVE-2021-30953Apple iOS 和 iPadOS 缓冲区错误漏洞
CVE-2021-30952Apple iOS 和 iPadOS 输入验证错误漏洞
CVE-2021-30940Apple macOS 缓冲区错误漏洞

Showing top 20 of 152 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-30862

No comments yet


Leave a comment