Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 8.8 CVE-2017-17515 etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might all… Debian Linux Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17516 scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER … Reddit Terminal Viewer Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17517 libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which … Sylpheed after 3.6 Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17518 swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specified by the BROWSER environment… White Dune Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17519 batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the program specified by the BRO… Ocaml Batteries Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17520 tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might a… Tin Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17521 uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which mi… Fontforge after 20170731 Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17522 Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which… Python after 3.6.3 Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17524 library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, whic… Swi Prolog Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17525 guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variabl… Postbooks Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17526 Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which… Giac Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17527 delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the BROWSER environment variable… Debian Linux Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17528 backends/platform/sdl/posix/posix.cpp in ScummVM 1.9.0 does not validate strings before launching the program specified by the BROWSER environment va… Scummvm Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17529 af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, wh… Abiword Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17530 common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might all… Geomview No fix yet Fix from $1,9502017-12-14 HIGH 7.5 CVE-2017-16680 Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller servic… Hana Extended Application Services Mitigation only Fix from $1,9502017-12-12 CRITICAL 9.8 CVE-2017-15708EPSS 18% In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases… Synapse Mitigation only Fix from $2,3002017-12-11 HIGH 8.8 CVE-2017-17512 sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable… Sensible Utils 0.0.11+ Fix from $1,9502017-12-11 HIGH 8.8 CVE-2017-17523 lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, whic… Lilypond Patch available Fix from $1,9502017-12-11 HIGH 8.8 CVE-2017-1000217 Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrar… Opencast after 2.3.2 Fix from $1,9502017-11-17 HIGH 7.5 CVE-2017-16719 An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 … Nport 5110 Firmware after 3.7 Fix from $1,9502017-11-16 CRITICAL 9.8 CVE-2017-8809EPSS 8% api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability. Debian Linux after 1.27.3 Fix from $2,3002017-11-15 CRITICAL 9.8 CVE-2017-5636 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio… Nifi Mitigation only Fix from $2,3002017-10-19 HIGH 8.8 CVE-2015-5227 The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter. Wordpress Landing Pages after 1.9.1 Fix from $1,9502017-10-18 CRITICAL 9.1 CVE-2015-7544 redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the Supe… Enterprise Virtualization Manager Mitigation only Fix from $2,3002017-09-25 HIGH 8.1 CVE-2015-4075EPSS 7% The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task. Helpdesk Pro after 1.3.0 Fix from $1,9502017-09-20 CRITICAL 9.8 CVE-2017-14397 AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability. Anydesk after 3.6.0 Fix from $2,3002017-09-12 MEDIUM 6.3 CVE-2016-2980 The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerabi… Sametime Patch available Fix from $1,6002017-08-29 CRITICAL 9.8 CVE-2017-9861 An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerab… Sunny Boy 3600 Firmware Mitigation only Fix from $2,3002017-08-05 MEDIUM 6.7 CVE-2017-6748 A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection… Web Security Appliance Mitigation only Fix from $1,6002017-07-25