Skip to main content

Vendor archive

att CVEs

Beta · best-effort

27 CVEs tagged to vendor att11 Critical, 12 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-26507

Published Apr 14, 2022

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as an…

CVSS 9.8 · Critical

CVE-2021-21811

Published Aug 31, 2021

A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overf…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21828

Published Aug 20, 2021

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case of DecodeTreeBlock a label is…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21827

Published Aug 20, 2021

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21826

Published Aug 20, 2021

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21825

Published Aug 18, 2021

A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI fil…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21810

Published Aug 17, 2021

A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21815

Published Aug 13, 2021

A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7. Within the function HandleFileArg the argument…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21814

Published Aug 13, 2021

Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21813

Published Aug 13, 2021

Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to memcpy copying th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21812

Published Aug 13, 2021

A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7. Within the function HandleFileArg the argument…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21830

Published Aug 13, 2021

A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-21829

Published Aug 13, 2021

A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-22650

Published Jul 19, 2021

A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm ev…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6029

Published Dec 4, 2013

Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1511

Published Mar 3, 2003

The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0167

Published May 3, 2001

Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0168

Published May 3, 2001

Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the De…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2