📦 Xmill

by Att

🔍 What is Xmill?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-26507

CRITICAL CVSS 9.8 Apr 14, 2022

CVE-2022-26507 is a critical heap-based buffer overflow vulnerability in AT&T Labs Xmill 0.7's XML decompression function. It allows remote attackers to execute arbitrary code by providing a specially...

CVE-2021-21811

CRITICAL CVSS 9.8 Aug 31, 2021

CVE-2021-21811 is a critical heap buffer overflow vulnerability in Xmill 0.7's XML parser that allows memory corruption via specially crafted XML files. Attackers can exploit this to execute arbitrary...

CVE-2021-21826

CRITICAL CVSS 9.8 Aug 20, 2021

A heap-based buffer overflow vulnerability in AT&T Labs Xmill 0.7 allows remote code execution when processing malicious XMI files. Attackers can exploit this by providing specially crafted files to t...

CVE-2021-21828

CRITICAL CVSS 9.8 Aug 20, 2021

This heap-based buffer overflow vulnerability in Xmill 0.7's XML decompression allows attackers to execute arbitrary code by providing a malicious file. It affects systems using Xmill for XML compress...

CVE-2021-21825

CRITICAL CVSS 9.8 Aug 18, 2021

This vulnerability allows remote code execution via a heap-based buffer overflow when processing specially crafted XMI files in Xmill 0.7. Attackers can exploit this by providing malicious files to tr...

CVE-2021-21810

CRITICAL CVSS 9.8 Aug 17, 2021

CVE-2021-21810 is a critical heap buffer overflow vulnerability in Xmill 0.7's XML parser that allows attackers to execute arbitrary code or cause denial of service by providing a malicious XML file. ...

CVE-2021-21829

CRITICAL CVSS 9.8 Aug 13, 2021

CVE-2021-21829 is a critical heap-based buffer overflow vulnerability in Xmill 0.7's XML decompression functionality that allows remote code execution via malicious XMI files. This affects any system ...

CVE-2021-21813

HIGH CVSS 7.8 Aug 13, 2021

CVE-2021-21813 is a stack-buffer overflow vulnerability in the HandleFileArg function where user-controlled command-line input is copied without length validation. This allows attackers to execute arb...

CVE-2021-21815

HIGH CVSS 7.8 Aug 13, 2021

This vulnerability allows attackers to execute arbitrary code on systems running Xmill 0.7 by exploiting a stack-based buffer overflow in the command-line argument parser. Attackers can craft maliciou...