Записи att
29 опубликованных записей вендора att.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 10,3 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-122 Heap-based Buffer Overflow4
- CWE-787 Out-of-bounds Write4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-798 Use of Hard-coded Credentials2
- CWE-287 Improper Authentication1
- CWE-326 Inadequate Encryption Strength1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2001-0168Готовый эксплойт | Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands att · winvnc | Критическая10,0 | — | 70,7 % | 3 мая 2001 г. |
45В плане | CVE-2001-0167Готовый эксплойт | Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands att · winvnc | Высокая7,6 | — | 50,8 % | 3 мая 2001 г. |
41В плане | CVE-1999-1059Эксплойта нет | Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.att · svr4 | Критическая10,0 | — | 4,2 % | 25 февр. 1992 г. |
40В плане | CVE-2021-21829Эксплойта нет | A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labatt · xmill · CWE-122 | Критическая9,8 | — | 2,5 % | 13 авг. 2021 г. |
40В плане | CVE-2022-26507Эксплойта нет | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7.att · xmill · CWE-787 | Критическая9,8 | — | 2,4 % | 14 апр. 2022 г. |
40В плане | CVE-2021-21825Эксплойта нет | A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’att · xmill · CWE-122 | Критическая9,8 | — | 2,3 % | 18 авг. 2021 г. |
40В плане | CVE-2021-21830Эксплойта нет | A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-122 | Критическая9,8 | — | 2,3 % | 13 авг. 2021 г. |
39Наблюдать | CVE-2021-21828Эксплойта нет | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Критическая9,8 | — | 1,1 % | 20 авг. 2021 г. |
39Наблюдать | CVE-2021-21810Эксплойта нет | A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-122 | Критическая9,8 | — | 1,1 % | 17 авг. 2021 г. |
39Наблюдать | CVE-2021-21811Эксплойта нет | A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-191 | Критическая9,8 | — | 1,1 % | 31 авг. 2021 г. |
39Наблюдать | CVE-2021-21826Эксплойта нет | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Критическая9,8 | — | 1,1 % | 20 авг. 2021 г. |
39Наблюдать | CVE-2021-21827Эксплойта нет | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Критическая9,8 | — | 1,1 % | 20 авг. 2021 г. |
36Наблюдать | CVE-2000-1164Эксплойта нет | WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows usatt · winvnc | Критическая9,0 | — | 1,5 % | 9 янв. 2001 г. |
33Наблюдать | CVE-2017-14115Эксплойта нет | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanentatt · u-verse firmware · CWE-798 | Высокая8,1 | — | 4,4 % | 3 сент. 2017 г. |
33Наблюдать | CVE-2017-14116Эксплойта нет | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver att · u-verse firmware · CWE-798 | Высокая8,1 | — | 3,3 % | 3 сент. 2017 г. |
33Наблюдать | CVE-2017-10793Эксплойта нет | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, confatt · u-verse firmware · CWE-200 | Высокая8,1 | — | 2,8 % | 3 сент. 2017 г. |
31Наблюдать | CVE-2001-1422Эксплойта нет | WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authenticatt · winvnc | Высокая7,5 | — | 2,1 % | 23 янв. 2001 г. |
31Наблюдать | CVE-2021-21814Эксплойта нет | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.att · xmill · CWE-88 | Высокая7,8 | — | 0,3 % | 13 авг. 2021 г. |
31Наблюдать | CVE-2021-21813Эксплойта нет | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.att · xmill · CWE-787 | Высокая7,8 | — | 0,3 % | 13 авг. 2021 г. |
31Наблюдать | CVE-2021-21815Эксплойта нет | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7.att · xmill · CWE-787 | Высокая7,8 | — | 0,3 % | 13 авг. 2021 г. |
31Наблюдать | CVE-2021-21812Эксплойта нет | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-787 | Высокая7,8 | — | 0,3 % | 13 авг. 2021 г. |
30Наблюдать | CVE-2013-7286Эксплойта нет | MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithmatt · mobileiron sentry · CWE-326 | Высокая7,5 | — | 1,5 % | 12 февр. 2020 г. |
30Наблюдать | CVE-2020-22650Эксплойта нет | A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the oatt · alienvault ossim · CWE-401 | Высокая7,5 | — | 1,1 % | 19 июл. 2021 г. |
29Наблюдать | CVE-2012-2980Эксплойта нет | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Chahtc · chacha · CWE-255 | Высокая7,1 | — | 1,8 % | 21 авг. 2012 г. |
28Наблюдать | CVE-2013-6029Эксплойта нет | Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitraratt · connect participant application · CWE-119 | Средняя6,8 | — | 2,5 % | 4 дек. 2013 г. |
- CVE-2001-016861На этой неделе
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands
КритическаяCVSS 10,0Готовый эксплойтEPSS 71 %att · winvnc3 мая 2001 г.
- CVE-2001-016745В плане
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands
ВысокаяCVSS 7,6Готовый эксплойтEPSS 51 %att · winvnc3 мая 2001 г.
- CVE-1999-105941В плане
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %att · svr425 февр. 1992 г.
- CVE-2021-2182940В плане
A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Lab
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %att · xmill13 авг. 2021 г.
- CVE-2022-2650740В плане
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %att · xmill14 апр. 2022 г.
- CVE-2021-2182540В плане
A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %att · xmill18 авг. 2021 г.
- CVE-2021-2183040В плане
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %att · xmill13 авг. 2021 г.
- CVE-2021-2182839Наблюдать
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %att · xmill20 авг. 2021 г.
- CVE-2021-2181039Наблюдать
A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %att · xmill17 авг. 2021 г.
- CVE-2021-2181139Наблюдать
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %att · xmill31 авг. 2021 г.
- CVE-2021-2182639Наблюдать
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %att · xmill20 авг. 2021 г.
- CVE-2021-2182739Наблюдать
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %att · xmill20 авг. 2021 г.
- CVE-2000-116436Наблюдать
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows us
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %att · winvnc9 янв. 2001 г.
- CVE-2017-1411533Наблюдать
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent
ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %att · u-verse firmware3 сент. 2017 г.
- CVE-2017-1411633Наблюдать
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %att · u-verse firmware3 сент. 2017 г.
- CVE-2017-1079333Наблюдать
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, conf
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %att · u-verse firmware3 сент. 2017 г.
- CVE-2001-142231Наблюдать
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentic
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %att · winvnc23 янв. 2001 г.
- CVE-2021-2181431Наблюдать
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %att · xmill13 авг. 2021 г.
- CVE-2021-2181331Наблюдать
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %att · xmill13 авг. 2021 г.
- CVE-2021-2181531Наблюдать
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %att · xmill13 авг. 2021 г.
- CVE-2021-2181231Наблюдать
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %att · xmill13 авг. 2021 г.
- CVE-2013-728630Наблюдать
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %att · mobileiron sentry12 февр. 2020 г.
- CVE-2020-2265030Наблюдать
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the o
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %att · alienvault ossim19 июл. 2021 г.
- CVE-2012-298029Наблюдать
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Cha
ВысокаяCVSS 7,1Эксплойта нетEPSS 2 %htc · chacha21 авг. 2012 г.
- CVE-2013-602928Наблюдать
Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrar
СредняяCVSS 6,8Эксплойта нетEPSS 3 %att · connect participant application4 дек. 2013 г.