Xmill
Vendor:
First CVE: Aug 13, 2021 · Active for 4 years
13
Total CVEs
More Total CVEs than 91% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
9.2
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xmill over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 13, 2021
4 years ago
Most Recent CVE
Apr 14, 2022
1,562 days ago
CVE Severity & Scoring
Xmill13 CVEs
31%
69%
All CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local4 (30.8%)
Network9 (69.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None9 (69.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26507CRITICAL A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any | Apr 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-21828CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case of DecodeTreeBlock a label is c | Aug 20, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21830CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote co | Aug 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21829CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI fi | Aug 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21827CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the | Aug 20, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21826CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the | Aug 20, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21825CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file | Aug 18, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21811CRITICAL A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overfl | Aug 31, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-21810CRITICAL A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An | Aug 17, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-21815HIGH A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7. Within the function HandleFileArg the argument f | Aug 13, 2021 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Xmill
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.7 | 13 | 9.2 | 1.3% | 0 | 0 |