Products: 12
    Vulnerabilities: 30
    Known Exploited: 0
    12
    Critical Level Threats
    13
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-13982

    SPON IP Network Intercom System rj_get_token.php Arbitrary File Read

    Last Modified: Jul 28, 2026
    Published: Aug 27, 2025

    CVE-2022-26507

    A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Last Modified: Nov 21, 2024
    Published: Apr 14, 2022

    CVE-2021-21811

    A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

    Last Modified: Nov 21, 2024
    Published: Aug 31, 2021

    CVE-2021-21828

    A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case of DecodeTreeBlock a label is created via CurPath::AddLabel in order to track the label for later reference. An attacker can provide a malicious file to trigger this vulnerability.

    Last Modified: Nov 21, 2024
    Published: Aug 20, 2021

    CVE-2021-21827

    A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer. An attacker can provide a malicious file to trigger this vulnerability.

    Last Modified: Nov 21, 2024
    Published: Aug 20, 2021
    Items Per Page
    Att Vulnerabilities & Security CVEs | CVE-DB