att records
29 published records for vendor att.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 10.3%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-122 Heap-based Buffer Overflow4
- CWE-787 Out-of-bounds Write4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-798 Use of Hard-coded Credentials2
- CWE-287 Improper Authentication1
- CWE-326 Inadequate Encryption Strength1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2001-0168Weaponized | Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands att · winvnc | Critical10.0 | — | 70.7% | May 3, 2001 |
45Plan | CVE-2001-0167Weaponized | Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands att · winvnc | High7.6 | — | 50.8% | May 3, 2001 |
41Plan | CVE-1999-1059No exploit | Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.att · svr4 | Critical10.0 | — | 4.2% | Feb 25, 1992 |
40Plan | CVE-2021-21829No exploit | A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labatt · xmill · CWE-122 | Critical9.8 | — | 2.5% | Aug 13, 2021 |
40Plan | CVE-2022-26507No exploit | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7.att · xmill · CWE-787 | Critical9.8 | — | 2.4% | Apr 14, 2022 |
40Plan | CVE-2021-21825No exploit | A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’att · xmill · CWE-122 | Critical9.8 | — | 2.3% | Aug 18, 2021 |
40Plan | CVE-2021-21830No exploit | A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-122 | Critical9.8 | — | 2.3% | Aug 13, 2021 |
39Monitor | CVE-2021-21828No exploit | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Critical9.8 | — | 1.1% | Aug 20, 2021 |
39Monitor | CVE-2021-21810No exploit | A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-122 | Critical9.8 | — | 1.1% | Aug 17, 2021 |
39Monitor | CVE-2021-21811No exploit | A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-191 | Critical9.8 | — | 1.1% | Aug 31, 2021 |
39Monitor | CVE-2021-21826No exploit | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Critical9.8 | — | 1.1% | Aug 20, 2021 |
39Monitor | CVE-2021-21827No exploit | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Critical9.8 | — | 1.1% | Aug 20, 2021 |
36Monitor | CVE-2000-1164No exploit | WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows usatt · winvnc | Critical9.0 | — | 1.5% | Jan 9, 2001 |
33Monitor | CVE-2017-14115No exploit | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanentatt · u-verse firmware · CWE-798 | High8.1 | — | 4.4% | Sep 3, 2017 |
33Monitor | CVE-2017-14116No exploit | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver att · u-verse firmware · CWE-798 | High8.1 | — | 3.3% | Sep 3, 2017 |
33Monitor | CVE-2017-10793No exploit | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, confatt · u-verse firmware · CWE-200 | High8.1 | — | 2.8% | Sep 3, 2017 |
31Monitor | CVE-2001-1422No exploit | WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authenticatt · winvnc | High7.5 | — | 2.1% | Jan 23, 2001 |
31Monitor | CVE-2021-21814No exploit | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.att · xmill · CWE-88 | High7.8 | — | 0.3% | Aug 13, 2021 |
31Monitor | CVE-2021-21813No exploit | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.att · xmill · CWE-787 | High7.8 | — | 0.3% | Aug 13, 2021 |
31Monitor | CVE-2021-21815No exploit | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7.att · xmill · CWE-787 | High7.8 | — | 0.3% | Aug 13, 2021 |
31Monitor | CVE-2021-21812No exploit | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-787 | High7.8 | — | 0.3% | Aug 13, 2021 |
30Monitor | CVE-2013-7286No exploit | MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithmatt · mobileiron sentry · CWE-326 | High7.5 | — | 1.5% | Feb 12, 2020 |
30Monitor | CVE-2020-22650No exploit | A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the oatt · alienvault ossim · CWE-401 | High7.5 | — | 1.1% | Jul 19, 2021 |
29Monitor | CVE-2012-2980No exploit | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Chahtc · chacha · CWE-255 | High7.1 | — | 1.8% | Aug 21, 2012 |
28Monitor | CVE-2013-6029No exploit | Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitraratt · connect participant application · CWE-119 | Medium6.8 | — | 2.5% | Dec 4, 2013 |
- CVE-2001-016861This week
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands
CriticalCVSS 10.0WeaponizedEPSS 71%att · winvncMay 3, 2001
- CVE-2001-016745Plan
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands
HighCVSS 7.6WeaponizedEPSS 51%att · winvncMay 3, 2001
- CVE-1999-105941Plan
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
CriticalCVSS 10.0No exploitEPSS 4%att · svr4Feb 25, 1992
- CVE-2021-2182940Plan
A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Lab
CriticalCVSS 9.8No exploitEPSS 3%att · xmillAug 13, 2021
- CVE-2022-2650740Plan
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7.
CriticalCVSS 9.8No exploitEPSS 2%att · xmillApr 14, 2022
- CVE-2021-2182540Plan
A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’
CriticalCVSS 9.8No exploitEPSS 2%att · xmillAug 18, 2021
- CVE-2021-2183040Plan
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7.
CriticalCVSS 9.8No exploitEPSS 2%att · xmillAug 13, 2021
- CVE-2021-2182839Monitor
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
CriticalCVSS 9.8No exploitEPSS 1%att · xmillAug 20, 2021
- CVE-2021-2181039Monitor
A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7.
CriticalCVSS 9.8No exploitEPSS 1%att · xmillAug 17, 2021
- CVE-2021-2181139Monitor
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7.
CriticalCVSS 9.8No exploitEPSS 1%att · xmillAug 31, 2021
- CVE-2021-2182639Monitor
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
CriticalCVSS 9.8No exploitEPSS 1%att · xmillAug 20, 2021
- CVE-2021-2182739Monitor
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
CriticalCVSS 9.8No exploitEPSS 1%att · xmillAug 20, 2021
- CVE-2000-116436Monitor
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows us
CriticalCVSS 9.0No exploitEPSS 2%att · winvncJan 9, 2001
- CVE-2017-1411533Monitor
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent
HighCVSS 8.1No exploitEPSS 4%att · u-verse firmwareSep 3, 2017
- CVE-2017-1411633Monitor
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver
HighCVSS 8.1No exploitEPSS 3%att · u-verse firmwareSep 3, 2017
- CVE-2017-1079333Monitor
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, conf
HighCVSS 8.1No exploitEPSS 3%att · u-verse firmwareSep 3, 2017
- CVE-2001-142231Monitor
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentic
HighCVSS 7.5No exploitEPSS 2%att · winvncJan 23, 2001
- CVE-2021-2181431Monitor
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.
HighCVSS 7.8No exploitEPSS 0%att · xmillAug 13, 2021
- CVE-2021-2181331Monitor
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.
HighCVSS 7.8No exploitEPSS 0%att · xmillAug 13, 2021
- CVE-2021-2181531Monitor
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7.
HighCVSS 7.8No exploitEPSS 0%att · xmillAug 13, 2021
- CVE-2021-2181231Monitor
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7.
HighCVSS 7.8No exploitEPSS 0%att · xmillAug 13, 2021
- CVE-2013-728630Monitor
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
HighCVSS 7.5No exploitEPSS 2%att · mobileiron sentryFeb 12, 2020
- CVE-2020-2265030Monitor
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the o
HighCVSS 7.5No exploitEPSS 1%att · alienvault ossimJul 19, 2021
- CVE-2012-298029Monitor
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Cha
HighCVSS 7.1No exploitEPSS 2%htc · chachaAug 21, 2012
- CVE-2013-602928Monitor
Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrar
MediumCVSS 6.8No exploitEPSS 3%att · connect participant applicationDec 4, 2013