Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Debian Linux HIGH 8.8
CVE-2017-17515

etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might all…

Mitigation only
Fix from $1,950 2017-12-14
Reddit Terminal Viewer HIGH 8.8
CVE-2017-17516

scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER …

Mitigation only
Fix from $1,950 2017-12-14
Sylpheed HIGH 8.8
CVE-2017-17517

libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which …

Fix: after 3.6
Fix from $1,950 2017-12-14
White Dune HIGH 8.8
CVE-2017-17518

swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specified by the BROWSER environment…

Mitigation only
Fix from $1,950 2017-12-14
Ocaml Batteries HIGH 8.8
CVE-2017-17519

batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the program specified by the BRO…

Mitigation only
Fix from $1,950 2017-12-14
Tin HIGH 8.8
CVE-2017-17520

tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might a…

Mitigation only
Fix from $1,950 2017-12-14
Fontforge HIGH 8.8
CVE-2017-17521

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which mi…

Fix: after 20170731
Fix from $1,950 2017-12-14
Python HIGH 8.8
CVE-2017-17522

Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which…

Fix: after 3.6.3
Fix from $1,950 2017-12-14
Swi Prolog HIGH 8.8
CVE-2017-17524

library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, whic…

Mitigation only
Fix from $1,950 2017-12-14
Postbooks HIGH 8.8
CVE-2017-17525

guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variabl…

Mitigation only
Fix from $1,950 2017-12-14
Giac HIGH 8.8
CVE-2017-17526

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17527

delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the BROWSER environment variable…

Mitigation only
Fix from $1,950 2017-12-14
Scummvm HIGH 8.8
CVE-2017-17528

backends/platform/sdl/posix/posix.cpp in ScummVM 1.9.0 does not validate strings before launching the program specified by the BROWSER environment va…

Mitigation only
Fix from $1,950 2017-12-14
Abiword HIGH 8.8
CVE-2017-17529

af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, wh…

Mitigation only
Fix from $1,950 2017-12-14
Geomview HIGH 8.8
CVE-2017-17530

common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might all…

No fix yet
Fix from $1,950 2017-12-14
Hana Extended Application Services HIGH 7.5
CVE-2017-16680

Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller servic…

Mitigation only
Fix from $1,950 2017-12-12
Synapse CRITICAL 9.8
CVE-2017-15708EPSS 18%

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases…

Mitigation only
Fix from $2,300 2017-12-11
Sensible Utils HIGH 8.8
CVE-2017-17512

sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable…

Fix: 0.0.11+
Fix from $1,950 2017-12-11
Lilypond HIGH 8.8
CVE-2017-17523

lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, whic…

Patch available
Fix from $1,950 2017-12-11
Opencast HIGH 8.8
CVE-2017-1000217

Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrar…

Fix: after 2.3.2
Fix from $1,950 2017-11-17
Nport 5110 Firmware HIGH 7.5
CVE-2017-16719

An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 …

Fix: after 3.7
Fix from $1,950 2017-11-16
Debian Linux CRITICAL 9.8
CVE-2017-8809EPSS 8%

api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.

Fix: after 1.27.3
Fix from $2,300 2017-11-15
Nifi CRITICAL 9.8
CVE-2017-5636

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…

Mitigation only
Fix from $2,300 2017-10-19
Wordpress Landing Pages HIGH 8.8
CVE-2015-5227

The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.

Fix: after 1.9.1
Fix from $1,950 2017-10-18
Enterprise Virtualization Manager CRITICAL 9.1
CVE-2015-7544

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe…

Mitigation only
Fix from $2,300 2017-09-25
Helpdesk Pro HIGH 8.1
CVE-2015-4075EPSS 7%

The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.

Fix: after 1.3.0
Fix from $1,950 2017-09-20
Anydesk CRITICAL 9.8
CVE-2017-14397

AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.

Fix: after 3.6.0
Fix from $2,300 2017-09-12
Sametime MEDIUM 6.3
CVE-2016-2980

The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerabi…

Patch available
Fix from $1,600 2017-08-29
Sunny Boy 3600 Firmware CRITICAL 9.8
CVE-2017-9861

An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerab…

Mitigation only
Fix from $2,300 2017-08-05
Web Security Appliance MEDIUM 6.7
CVE-2017-6748

A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection…

Mitigation only
Fix from $1,600 2017-07-25