<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:40:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04371</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04371</link>
      <description>bdu:2022-04371</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04371</guid>
    </item>
    <item>
      <title>certfr-2022-avi-628 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-628</link>
      <description>certfr-2022-avi-628</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-628</guid>
    </item>
    <item>
      <title>EUVD-2026-14942</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-14942</link>
      <description>EUVD-2026-14942</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-14942</guid>
    </item>
    <item>
      <title>fkie_cve-2022-26507</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-26507</link>
      <description>&lt;p&gt;A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&amp;amp;T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&amp;amp;T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-26507</guid>
    </item>
    <item>
      <title>GHSA-92r8-w862-f2pj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-92r8-w862-f2pj</link>
      <description>&lt;p&gt;** UNSUPPORTED WHEN ASSIGNED ** A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&amp;amp;T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;** UNSUPPORTED WHEN ASSIGNED ** A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&amp;amp;T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-92r8-w862-f2pj</guid>
    </item>
    <item>
      <title>gsd-2022-26507</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-26507</link>
      <description>gsd-2022-26507</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-26507</guid>
    </item>
    <item>
      <title>ICSA-22-223-03 — Schneider Electric EcoStruxure, EcoStruxure Process Expert, SCADAPack RemoteConnect for x70</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-223-03</link>
      <description>&lt;p&gt;A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21810 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression. PlainTextUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file could lead to remote code execution. An attacker could provide a malicious file to trigger this vulnerability.CVE-2021-21825 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21829 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21810 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression. PlainTextUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file could lead to remote code execution. An attacker could provide a malicious file to trigger this vulnerability.CVE-2021-21825 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21829 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&amp;amp;T Labs &amp;#39; Xmill 0.7. A specially crafted XML file can…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-223-03</guid>
    </item>
    <item>
      <title>SEVD-2021-222-02 — AT&amp;T Labs Compressor (XMilI) and Decompressor (XDemill) used by EcoStruxureTM Control Expert, EcoStruxureTM Process Exp…</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-222-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities on AT&amp;amp;T Labs’ Compressor (XMilI) and decompressor (XDemill) third party components used by EcoStruxure Control Expert, EcoStruxure Process Expert and SCADAPack RemoteConnect™ for x70.&#13;
Failure to apply the mitigations provided below may lead to the execution of a malicious file, which could result in code execution with elevated privileges on the engineering workstation. For an attack to be successful, an attacker requires access to the engineering workstation and then needs to trick a valid user to run a script or load a malicious project file.&#13;
July 2022 Update: A release is available for SCADAPack RemoteConnect™ R2.7.3 that addresses workstation vulnerabilities related to the issues listed below.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities on AT&amp;amp;T Labs’ Compressor (XMilI) and decompressor (XDemill) third party components used by EcoStruxure Control Expert, EcoStruxure Process Expert and SCADAPack RemoteConnect™ for x70.&#13;
Failure to apply the mitigations provided below may lead to the execution of a malicious file, which could result in code execution with elevated privileges on the engineering workstation. For an attack to be successful, an attacker requires access to the engineering workstation and then needs to trick a valid user to run a script or load a malicious project file.&#13;
July 2022 Update: A release is available for SCADAPack RemoteConnect™ R2.7.3 that addresses workstation vulnerabilities related to the issues listed below.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-222-02</guid>
    </item>
  </channel>
</rss>
