|
250081
|
8.8 |
HIGH
Network
|
xtuple
|
postbooks
|
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct a…
|
CWE-74
Injection
|
CVE-2017-17525
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250082
|
8.8 |
HIGH
Network
|
swi-prolog
|
swi-prolog
|
library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument…
|
CWE-74
Injection
|
CVE-2017-17524
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250083
|
8.8 |
HIGH
Network
|
python
|
python
|
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-…
|
CWE-74
Injection
|
CVE-2017-17522
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250084
|
8.8 |
HIGH
Network
|
fontforge
|
fontforge
|
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-inj…
|
CWE-74
Injection
|
CVE-2017-17521
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250085
|
8.8 |
HIGH
Network
|
debian
|
tin
|
tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injectio…
|
CWE-74
Injection
|
CVE-2017-17520
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250086
|
8.8 |
HIGH
Network
|
ocaml_batteries_project
|
ocaml_batteries
|
batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remot…
|
CWE-74
Injection
|
CVE-2017-17519
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250087
|
8.8 |
HIGH
Network
|
white_dune_project
|
white_dune
|
swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to c…
|
CWE-74
Injection
|
CVE-2017-17518
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250088
|
8.8 |
HIGH
Network
|
sylpheed_project
|
sylpheed
|
libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-i…
|
CWE-74
Injection
|
CVE-2017-17517
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250089
|
8.8 |
HIGH
Network
|
reddit_terminal_viewer_project
|
reddit_terminal_viewer
|
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote att…
|
CWE-74
Injection
|
CVE-2017-17516
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250090
|
8.8 |
HIGH
Network
|
ecmwf debian
|
metview debian_linux
|
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection …
|
CWE-74
Injection
|
CVE-2017-17515
|
2024-11-21 12:18 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|