Known Vulnerabilities for products from Attachmate

Listed below are 10 of the newest known vulnerabilities associated with the vendor "Attachmate".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2014-5211 json Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbi... Not Provided 2015-01-27 2026-05-06
CVE-2014-0607 json Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote a... Not Provided 2014-07-24 2026-05-06
CVE-2014-0605 json Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allo... Not Provided 2015-02-06 2026-05-06
CVE-2014-0604 json Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allo... Not Provided 2015-02-06 2026-05-06
CVE-2014-0603 json The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial... Not Provided 2015-02-06 2026-05-06
CVE-2013-3626 json Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 H... Not Provided 2013-11-06 2026-04-29
CVE-2011-5157 json Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Troj... Not Provided 2012-09-06 2026-04-29
CVE-2011-5012 json Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attac... Not Provided 2011-12-25 2026-04-29
CVE-2010-4146 json Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1,... Not Provided 2010-11-02 2026-04-29
CVE-2008-6021 json Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknow... Not Provided 2009-02-02 2026-04-23

Known software with vulnerabilities from Attachmate

Type Vendor Product Version
ApplicationAttachmateExtra! For Windows 95/nt6.4
ApplicationAttachmateInfoconnect Enterprise Edition7.50.0000
ApplicationAttachmateInfoconnect For Unisys9.0.1393
ApplicationAttachmateInfoconnect Options Pack8.00.0000
ApplicationAttachmateInstaller Service8.00.0001
ApplicationAttachmateOracle Provider1.0.0
ApplicationAttachmateReflection Administrators Toolkit14.0.3670
ApplicationAttachmateReflection For Hp14.0
ApplicationAttachmateReflection For Ibm14.0
ApplicationAttachmateReflection For Regis Graphics Server14.0
ApplicationAttachmateReflection For Secure It6.0
ApplicationAttachmateReflection For Secure It Client7.0.96
ApplicationAttachmateReflection For Secure It Server6.0_build_15
ApplicationAttachmateReflection For The Web 200810.1.549
ApplicationAttachmateReflection For Unix And Openvms14.0
ApplicationAttachmateReflection Pki Services Manager1.1.70
ApplicationAttachmateReflection Standard Suite15.3.436_
ApplicationAttachmateReflection X13.0.0307
ApplicationAttachmateVerastream Host Integrator4.5
ApplicationAttachmateVerastream Process Designer6.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report