<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:28:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03272</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03272</link>
      <description>bdu:2023-03272</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03272</guid>
    </item>
    <item>
      <title>certfr-2021-avi-622 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</link>
      <description>certfr-2021-avi-622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</guid>
    </item>
    <item>
      <title>EUVD-2026-22521</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-22521</link>
      <description>EUVD-2026-22521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-22521</guid>
    </item>
    <item>
      <title>fkie_cve-2021-21814</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21814</link>
      <description>&lt;p&gt;Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, no checks are done to see if the passed in char* is longer than the staticly sized buffer data is memcpy‘d into, but after the memcpy a null byte is written to what is assumed to be the end of the buffer to terminate the char*, but without length checks, this null write occurs at an arbitrary offset from the buffer. An attacker can provide malicious input to trigger this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, no checks are done to see if the passed in char* is longer than the staticly sized buffer data is memcpy‘d into, but after the memcpy a null byte is written to what is assumed to be the end of the buffer to terminate the char*, but without length checks, this null write occurs at an arbitrary offset from the buffer. An attacker can provide malicious input to trigger this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-21814</guid>
    </item>
    <item>
      <title>GHSA-9m22-mqrh-x6c3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9m22-mqrh-x6c3</link>
      <description>&lt;p&gt;Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, no checks are done to see if the passed in char* is longer than the staticly sized buffer data is memcpy‘d into, but after the memcpy a null byte is written to what is assumed to be the end of the buffer to terminate the char*, but without length checks, this null write occurs at an arbitrary offset from the buffer. An attacker can provide malicious input to trigger this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, no checks are done to see if the passed in char* is longer than the staticly sized buffer data is memcpy‘d into, but after the memcpy a null byte is written to what is assumed to be the end of the buffer to terminate the char*, but without length checks, this null write occurs at an arbitrary offset from the buffer. An attacker can provide malicious input to trigger this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9m22-mqrh-x6c3</guid>
    </item>
    <item>
      <title>gsd-2021-21814</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-21814</link>
      <description>gsd-2021-21814</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-21814</guid>
    </item>
    <item>
      <title>ICSA-22-223-03 — Schneider Electric EcoStruxure, EcoStruxure Process Expert, SCADAPack RemoteConnect for x70</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-223-03</link>
      <description>&lt;p&gt;A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21810 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression. PlainTextUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file could lead to remote code execution. An attacker could provide a malicious file to trigger this vulnerability.CVE-2021-21825 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21829 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21810 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression. PlainTextUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file could lead to remote code execution. An attacker could provide a malicious file to trigger this vulnerability.CVE-2021-21825 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21829 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-223-03</guid>
    </item>
    <item>
      <title>SEVD-2021-222-02 — AT&amp;T Labs Compressor (XMilI) and Decompressor (XDemill) used by EcoStruxureTM Control Expert, EcoStruxureTM Process Exp…</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-222-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities on AT&amp;amp;T Labs’ Compressor (XMilI) and decompressor (XDemill) third party components used by EcoStruxure Control Expert, EcoStruxure Process Expert and SCADAPack RemoteConnect™ for x70.&#13;
Failure to apply the mitigations provided below may lead to the execution of a malicious file, which could result in code execution with elevated privileges on the engineering workstation. For an attack to be successful, an attacker requires access to the engineering workstation and then needs to trick a valid user to run a script or load a malicious project file.&#13;
July 2022 Update: A release is available for SCADAPack RemoteConnect™ R2.7.3 that addresses workstation vulnerabilities related to the issues listed below.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities on AT&amp;amp;T Labs’ Compressor (XMilI) and decompressor (XDemill) third party components used by EcoStruxure Control Expert, EcoStruxure Process Expert and SCADAPack RemoteConnect™ for x70.&#13;
Failure to apply the mitigations provided below may lead to the execution of a malicious file, which could result in code execution with elevated privileges on the engineering workstation. For an attack to be successful, an attacker requires access to the engineering workstation and then needs to trick a valid user to run a script or load a malicious project file.&#13;
July 2022 Update: A release is available for SCADAPack RemoteConnect™ R2.7.3 that addresses workstation vulnerabilities related to the issues listed below.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-222-02</guid>
    </item>
  </channel>
</rss>
