Xerox DocuShare AMI Pro File Parsing Stack Overflow Vulnerability

February 23, 2022 No Comments
EIP-db4e064b A stack-based buffer overflow vulnerability exists within Xerox DocuShare. Exploitation of the vulnerability allows for attackers to execute arbitrary code with system privileges. The specific flaw exists within the parsing of AMI Pro (.sam) file formats. Parsing of this file structure
Read More »

Xerox DocuShare WordPerfect Parsing Stack Overflow Vulnerability

February 23, 2022 No Comments
EIP-c728d1ef A stack-based buffer overflow vulnerability exists within Xerox DocuShare. Exploitation of the vulnerability allows for attackers to execute arbitrary code with system privileges. The specific flaw exists within the parsing of containers embedded in WordPerfect (.wpd) file formats. Parsing of this
Read More »

Xerox DocuShare AMI Pro p-tag Parsing Stack Overflow Vulnerability

February 23, 2022 No Comments
EIP-6185db3e A stack-based buffer overflow vulnerability exists within Xerox DocuShare. Exploitation of the vulnerability allows for attackers to execute arbitrary code with system privileges. The specific flaw exists within the parsing of “<:p tags” embedded in AMI Pro (.sam) file formats. Parsing
Read More »

ZyXEL Armor Cross-Site Request Forgery Vulnerability

February 22, 2022 No Comments
EIP-521a3b40 A cross-site request forgery vulnerability exists within the ZyXEL Armor Z1 AC2350 and Z2 AC2600 series. Exploitation of the vulnerability allows for attackers to run arbitrary commands on vulnerable versions of the firmware under the context of the root user. Exploitation
Read More »

ZyXEL Armor Photobak Command Injection Vulnerability

February 22, 2022 No Comments
EIP-c624ba9f A command-injection vulnerability exists within the ZyXEL Armor Z1 AC2350 series. The vulnerable endpoint is within the ‘photobak’ component found in the cgi-bin. Exploitation of the vulnerability allows for remote unauthenticated attackers to run arbitrary commands on vulnerable versions of the
Read More »

Zlibc Environment Variable Handling Local Privilege Escalation Vulnerability

February 2, 2022 No Comments
EIP-1a8a439f A vulnerability exists in Zlibc that allows a local attacker to execute arbitrary code with elevated privileges through manipulation of the LD_ZLIB_CONFFILE and LD_ZLIB_UNCOMPRESSOR environment variables when calling setuid binaries. Vulnerability Identifiers Exodus Intelligence: EIP-1a8a439f MITRE CVE: N/A Vulnerability Metrics CVSSv2 Score:
Read More »

Arris SURFboard SSDP Command Injection Vulnerability

February 2, 2022 No Comments
EIP-55f127ea A vulnerability exists within Arris SURFboard’s handling of Simple Service Discovery Protocol (SSDP) messages. A specially crafted NOTIFY message with a LOCATION header can result in a command injection under the context of the root user. Vulnerability Identifiers Exodus Intelligence: EIP-55f127ea MITRE
Read More »

LiveAction LiveNX AWS Credential Disclosure Vulnerability

January 19, 2022 No Comments
EIP-7d4ec9e3 Several versions of LiveAction LiveNX network monitoring software contain Amazon Web Services (AWS) credentials. These credentials have privileged access to the LiveAction AWS infrastructure. A remote attacker may abuse these credentials to gain access to LiveAction internal resources. Vulnerability Identifiers Exodus Intelligence: EIP-7d4ec9e3
Read More »