attachmate records
10 published records for vendor attachmate.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2011-5012Proof of concept | Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflectioattachmate · reflection · CWE-119 | Critical10.0 | — | 7.8% | Dec 24, 2011 |
42Plan | CVE-2014-0605No exploit | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attacattachmate · reflection ftp client · CWE-22 | Critical10.0 | — | 7.7% | Feb 6, 2015 |
42Plan | CVE-2014-0604No exploit | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attacattachmate · reflection ftp client · CWE-22 | Critical10.0 | — | 6.3% | Feb 6, 2015 |
42Plan | CVE-2014-0603No exploit | The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (meattachmate · reflection ftp client · CWE-94 | Critical10.0 | — | 5.7% | Feb 6, 2015 |
41Plan | CVE-2014-0607No exploit | Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to exeattachmate · verastream process designer | Critical10.0 | — | 3.4% | Jul 24, 2014 |
41Plan | CVE-2008-6021No exploit | Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and atattachmate · reflection for secure it | Critical10.0 | — | 1.9% | Feb 2, 2009 |
38Monitor | CVE-2013-3626No exploit | Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remoattachmate · verastream host integrator · CWE-22 | Critical9.3 | — | 2.8% | Nov 6, 2013 |
28Monitor | CVE-2014-5211No exploit | Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via attachmate · reflection ftp client · CWE-119 | Medium6.8 | — | 2.8% | Jan 27, 2015 |
27Monitor | CVE-2011-5157No exploit | Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL inattachmate · reflection for hp | Medium6.9 | — | 0.4% | Sep 6, 2012 |
17Monitor | CVE-2010-4146No exploit | Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and eaattachmate · reflection for the web · CWE-79 | Medium4.3 | — | 1.1% | Nov 1, 2010 |
- CVE-2011-501242Plan
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflectio
CriticalCVSS 10.0Proof of conceptEPSS 8%attachmate · reflectionDec 24, 2011
- CVE-2014-060542Plan
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attac
CriticalCVSS 10.0No exploitEPSS 8%attachmate · reflection ftp clientFeb 6, 2015
- CVE-2014-060442Plan
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attac
CriticalCVSS 10.0No exploitEPSS 6%attachmate · reflection ftp clientFeb 6, 2015
- CVE-2014-060342Plan
The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (me
CriticalCVSS 10.0No exploitEPSS 6%attachmate · reflection ftp clientFeb 6, 2015
- CVE-2014-060741Plan
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to exe
CriticalCVSS 10.0No exploitEPSS 3%attachmate · verastream process designerJul 24, 2014
- CVE-2008-602141Plan
Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and at
CriticalCVSS 10.0No exploitEPSS 2%attachmate · reflection for secure itFeb 2, 2009
- CVE-2013-362638Monitor
Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remo
CriticalCVSS 9.3No exploitEPSS 3%attachmate · verastream host integratorNov 6, 2013
- CVE-2014-521128Monitor
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via
MediumCVSS 6.8No exploitEPSS 3%attachmate · reflection ftp clientJan 27, 2015
- CVE-2011-515727Monitor
Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in
MediumCVSS 6.9No exploitEPSS 0%attachmate · reflection for hpSep 6, 2012
- CVE-2010-414617Monitor
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and ea
MediumCVSS 4.3No exploitEPSS 1%attachmate · reflection for the webNov 1, 2010