Vulnerability index

Browse CVEs

28 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xmill CRITICAL 9.8
CVE-2022-26507

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code executi…

Fix: 15.1 / 2021+
Fix from $2,300 2022-04-14
Xmill CRITICAL 9.8
CVE-2021-21811

A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file c…

No fix yet
Fix from $2,300 2021-08-31
Xmill CRITICAL 9.8
CVE-2021-21826

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBl…

No fix yet
Fix from $2,300 2021-08-20
Xmill CRITICAL 9.8
CVE-2021-21827

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBl…

No fix yet
Fix from $2,300 2021-08-20
Xmill CRITICAL 9.8
CVE-2021-21828

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case …

No fix yet
Fix from $2,300 2021-08-20
Xmill CRITICAL 9.8
CVE-2021-21825

A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.…

No fix yet
Fix from $2,300 2021-08-18
Xmill CRITICAL 9.8
CVE-2021-21810

A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead…

No fix yet
Fix from $2,300 2021-08-17
Xmill HIGH 7.8
CVE-2021-21812

A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7. Within the functi…

No fix yet
Fix from $1,950 2021-08-13
Xmill HIGH 7.8
CVE-2021-21813

Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed…

No fix yet
Fix from $1,950 2021-08-13
Xmill HIGH 7.8
CVE-2021-21814

Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed…

No fix yet
Fix from $1,950 2021-08-13
Xmill HIGH 7.8
CVE-2021-21815

A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7. Within the functi…

No fix yet
Fix from $1,950 2021-08-13
Xmill CRITICAL 9.8
CVE-2021-21829

A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill …

No fix yet
Fix from $2,300 2021-08-13
Xmill CRITICAL 9.8
CVE-2021-21830

A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted…

No fix yet
Fix from $2,300 2021-08-13
Alienvault Ossim HIGH 7.5
CVE-2020-22650

A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence…

Mitigation only
Fix from $1,950 2021-07-19
Mobileiron Sentry HIGH 7.5
CVE-2013-7286

MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm

Fix: 5.0 / 5.9.1+
Fix from $1,950 2020-02-12
U Verse Firmware HIGH 8.1
CVE-2017-10793

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an…

No fix yet
Fix from $1,950 2017-09-03
U Verse Firmware HIGH 8.1
CVE-2017-14115

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable W…

No fix yet
Fix from $1,950 2017-09-03
U Verse Firmware HIGH 8.1
CVE-2017-14116

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https ser…

No fix yet
Fix from $1,950 2017-09-03
U Verse Firmware MEDIUM 5.9
CVE-2017-14117EPSS 8%

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated pro…

No fix yet
Fix from $1,600 2017-09-03
Connect Participant Application MEDIUM 6.8
CVE-2013-6029

Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code vi…

Fix: after 9.5.0
Fix from $1,600 2013-12-04
Status HIGH 7.1
CVE-2012-2980

The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T…

Mitigation only
Fix from $1,950 2012-08-21
Vnc MEDIUM 5.0
CVE-2002-1511

The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.

Patch available
Fix from $1,600 2003-03-03
Winvnc HIGH 10.0
CVE-2001-0168EPSS 71%

Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a lon…

Fix: after 3.3.3r7
Fix from $1,950 2001-05-03
Winvnc HIGH 7.6
CVE-2001-0167EPSS 51%

Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a lon…

Fix: after 3.3.3r7
Fix from $1,950 2001-05-03
Winvnc HIGH 7.5
CVE-2001-1422

WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by …

Fix: after 3.3.3
Fix from $1,950 2001-01-23
Winvnc HIGH 9.0
CVE-2000-1164

WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to re…

Patch available
Fix from $1,950 2001-01-09
Svr4 HIGH 10.0
CVE-1999-1059

Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.

Patch available
Fix from $1,950 1992-02-25
Svr4 HIGH 7.2
CVE-1999-1034

Vulnerability in login in AT&T System V Release 4 allows local users to gain privileges.

Patch available
Fix from $1,950 1991-05-23