<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:33:32.510562+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03276</id>
    <title>bdu:2023-03276</title>
    <updated>2026-10-03T22:33:32.593702+00:00</updated>
    <content>bdu:2023-03276</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</id>
    <title>certfr-2021-avi-622 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
    <updated>2026-10-03T22:33:32.593741+00:00</updated>
    <content>certfr-2021-avi-622</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-94931</id>
    <title>cnvd-2021-94931</title>
    <updated>2026-10-03T22:33:32.593759+00:00</updated>
    <content>cnvd-2021-94931</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-94931"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-22522</id>
    <title>EUVD-2026-22522</title>
    <updated>2026-10-03T22:33:32.593771+00:00</updated>
    <content>EUVD-2026-22522</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-22522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21812</id>
    <title>fkie_cve-2021-21812</title>
    <updated>2026-10-03T22:33:32.593781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&amp;T Labs’ Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a static sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-21812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pvj2-qmqv-76p3</id>
    <title>GHSA-pvj2-qmqv-76p3</title>
    <updated>2026-10-03T22:33:32.593813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&amp;T Labs’ Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a static sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pvj2-qmqv-76p3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-21812</id>
    <title>gsd-2021-21812</title>
    <updated>2026-10-03T22:33:32.593831+00:00</updated>
    <content>gsd-2021-21812</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-21812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-223-03</id>
    <title>ICSA-22-223-03 — Schneider Electric EcoStruxure, EcoStruxure Process Expert, SCADAPack RemoteConnect for x70</title>
    <updated>2026-10-03T22:33:32.593840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&amp;T Labs ' Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21810 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression. PlainTextUncompressor::UncompressItem functionality of AT&amp;T Labs ' Xmill 0.7. A specially crafted XMI file could lead to remote code execution. An attacker could provide a malicious file to trigger this vulnerability.CVE-2021-21825 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&amp;T Labs ' Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21829 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&amp;T Labs ' Xmill 0.7. A specially crafted XML file can…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-223-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2021-222-02</id>
    <title>SEVD-2021-222-02 — AT&amp;T Labs Compressor (XMilI) and Decompressor (XDemill) used by EcoStruxureTM Control Expert, EcoStruxureTM Process Exp…</title>
    <updated>2026-10-03T22:33:32.593894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities on AT&amp;T Labs’ Compressor (XMilI) and decompressor (XDemill) third party components used by EcoStruxure Control Expert, EcoStruxure Process Expert and SCADAPack RemoteConnect™ for x70.
Failure to apply the mitigations provided below may lead to the execution of a malicious file, which could result in code execution with elevated privileges on the engineering workstation. For an attack to be successful, an attacker requires access to the engineering workstation and then needs to trick a valid user to run a script or load a malicious project file.
July 2022 Update: A release is available for SCADAPack RemoteConnect™ R2.7.3 that addresses workstation vulnerabilities related to the issues listed below.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2021-222-02"/>
  </entry>
</feed>
