att kayıtları
att üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %10,3
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-122 Heap-based Buffer Overflow4
- CWE-787 Out-of-bounds Write4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-798 Use of Hard-coded Credentials2
- CWE-287 Improper Authentication1
- CWE-326 Inadequate Encryption Strength1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2001-0168Silahlaştırılmış | Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands att · winvnc | Kritik10,0 | — | %70,7 | 3 May 2001 |
45Planlayın | CVE-2001-0167Silahlaştırılmış | Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands att · winvnc | Yüksek7,6 | — | %50,8 | 3 May 2001 |
41Planlayın | CVE-1999-1059İstismar yok | Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.att · svr4 | Kritik10,0 | — | %4,2 | 25 Şub 1992 |
40Planlayın | CVE-2021-21829İstismar yok | A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labatt · xmill · CWE-122 | Kritik9,8 | — | %2,5 | 13 Ağu 2021 |
40Planlayın | CVE-2022-26507İstismar yok | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7.att · xmill · CWE-787 | Kritik9,8 | — | %2,4 | 14 Nis 2022 |
40Planlayın | CVE-2021-21825İstismar yok | A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’att · xmill · CWE-122 | Kritik9,8 | — | %2,3 | 18 Ağu 2021 |
40Planlayın | CVE-2021-21830İstismar yok | A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-122 | Kritik9,8 | — | %2,3 | 13 Ağu 2021 |
39İzleyin | CVE-2021-21828İstismar yok | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Kritik9,8 | — | %1,1 | 20 Ağu 2021 |
39İzleyin | CVE-2021-21810İstismar yok | A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-122 | Kritik9,8 | — | %1,1 | 17 Ağu 2021 |
39İzleyin | CVE-2021-21811İstismar yok | A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-191 | Kritik9,8 | — | %1,1 | 31 Ağu 2021 |
39İzleyin | CVE-2021-21826İstismar yok | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Kritik9,8 | — | %1,1 | 20 Ağu 2021 |
39İzleyin | CVE-2021-21827İstismar yok | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.att · xmill · CWE-120 | Kritik9,8 | — | %1,1 | 20 Ağu 2021 |
36İzleyin | CVE-2000-1164İstismar yok | WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows usatt · winvnc | Kritik9,0 | — | %1,5 | 9 Oca 2001 |
33İzleyin | CVE-2017-14115İstismar yok | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanentatt · u-verse firmware · CWE-798 | Yüksek8,1 | — | %4,4 | 3 Eyl 2017 |
33İzleyin | CVE-2017-14116İstismar yok | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver att · u-verse firmware · CWE-798 | Yüksek8,1 | — | %3,3 | 3 Eyl 2017 |
33İzleyin | CVE-2017-10793İstismar yok | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, confatt · u-verse firmware · CWE-200 | Yüksek8,1 | — | %2,8 | 3 Eyl 2017 |
31İzleyin | CVE-2001-1422İstismar yok | WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authenticatt · winvnc | Yüksek7,5 | — | %2,1 | 23 Oca 2001 |
31İzleyin | CVE-2021-21814İstismar yok | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.att · xmill · CWE-88 | Yüksek7,8 | — | %0,3 | 13 Ağu 2021 |
31İzleyin | CVE-2021-21813İstismar yok | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.att · xmill · CWE-787 | Yüksek7,8 | — | %0,3 | 13 Ağu 2021 |
31İzleyin | CVE-2021-21815İstismar yok | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7.att · xmill · CWE-787 | Yüksek7,8 | — | %0,3 | 13 Ağu 2021 |
31İzleyin | CVE-2021-21812İstismar yok | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7.att · xmill · CWE-787 | Yüksek7,8 | — | %0,3 | 13 Ağu 2021 |
30İzleyin | CVE-2013-7286İstismar yok | MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithmatt · mobileiron sentry · CWE-326 | Yüksek7,5 | — | %1,5 | 12 Şub 2020 |
30İzleyin | CVE-2020-22650İstismar yok | A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the oatt · alienvault ossim · CWE-401 | Yüksek7,5 | — | %1,1 | 19 Tem 2021 |
29İzleyin | CVE-2012-2980İstismar yok | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Chahtc · chacha · CWE-255 | Yüksek7,1 | — | %1,8 | 21 Ağu 2012 |
28İzleyin | CVE-2013-6029İstismar yok | Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitraratt · connect participant application · CWE-119 | Orta6,8 | — | %2,5 | 4 Ara 2013 |
- CVE-2001-016861Bu hafta
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands
KritikCVSS 10,0SilahlaştırılmışEPSS %71att · winvnc3 May 2001
- CVE-2001-016745Planlayın
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands
YüksekCVSS 7,6SilahlaştırılmışEPSS %51att · winvnc3 May 2001
- CVE-1999-105941Planlayın
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
KritikCVSS 10,0İstismar yokEPSS %4att · svr425 Şub 1992
- CVE-2021-2182940Planlayın
A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Lab
KritikCVSS 9,8İstismar yokEPSS %3att · xmill13 Ağu 2021
- CVE-2022-2650740Planlayın
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7.
KritikCVSS 9,8İstismar yokEPSS %2att · xmill14 Nis 2022
- CVE-2021-2182540Planlayın
A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’
KritikCVSS 9,8İstismar yokEPSS %2att · xmill18 Ağu 2021
- CVE-2021-2183040Planlayın
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7.
KritikCVSS 9,8İstismar yokEPSS %2att · xmill13 Ağu 2021
- CVE-2021-2182839İzleyin
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
KritikCVSS 9,8İstismar yokEPSS %1att · xmill20 Ağu 2021
- CVE-2021-2181039İzleyin
A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7.
KritikCVSS 9,8İstismar yokEPSS %1att · xmill17 Ağu 2021
- CVE-2021-2181139İzleyin
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7.
KritikCVSS 9,8İstismar yokEPSS %1att · xmill31 Ağu 2021
- CVE-2021-2182639İzleyin
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
KritikCVSS 9,8İstismar yokEPSS %1att · xmill20 Ağu 2021
- CVE-2021-2182739İzleyin
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7.
KritikCVSS 9,8İstismar yokEPSS %1att · xmill20 Ağu 2021
- CVE-2000-116436İzleyin
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows us
KritikCVSS 9,0İstismar yokEPSS %2att · winvnc9 Oca 2001
- CVE-2017-1411533İzleyin
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent
YüksekCVSS 8,1İstismar yokEPSS %4att · u-verse firmware3 Eyl 2017
- CVE-2017-1411633İzleyin
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver
YüksekCVSS 8,1İstismar yokEPSS %3att · u-verse firmware3 Eyl 2017
- CVE-2017-1079333İzleyin
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, conf
YüksekCVSS 8,1İstismar yokEPSS %3att · u-verse firmware3 Eyl 2017
- CVE-2001-142231İzleyin
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentic
YüksekCVSS 7,5İstismar yokEPSS %2att · winvnc23 Oca 2001
- CVE-2021-2181431İzleyin
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.
YüksekCVSS 7,8İstismar yokEPSS %0att · xmill13 Ağu 2021
- CVE-2021-2181331İzleyin
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line.
YüksekCVSS 7,8İstismar yokEPSS %0att · xmill13 Ağu 2021
- CVE-2021-2181531İzleyin
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7.
YüksekCVSS 7,8İstismar yokEPSS %0att · xmill13 Ağu 2021
- CVE-2021-2181231İzleyin
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7.
YüksekCVSS 7,8İstismar yokEPSS %0att · xmill13 Ağu 2021
- CVE-2013-728630İzleyin
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
YüksekCVSS 7,5İstismar yokEPSS %2att · mobileiron sentry12 Şub 2020
- CVE-2020-2265030İzleyin
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the o
YüksekCVSS 7,5İstismar yokEPSS %1att · alienvault ossim19 Tem 2021
- CVE-2012-298029İzleyin
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Cha
YüksekCVSS 7,1İstismar yokEPSS %2htc · chacha21 Ağu 2012
- CVE-2013-602928İzleyin
Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrar
OrtaCVSS 6,8İstismar yokEPSS %3att · connect participant application4 Ara 2013