Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-12-14 CVE-2017-17525 Injection vulnerability in Xtuple Postbooks 4.7.0
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
xtuple CWE-74
8.8
2017-12-14 CVE-2017-17524 Injection vulnerability in Swi-Prolog 7.2.3
library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
swi-prolog CWE-74
8.8
2017-12-14 CVE-2017-17522 Injection vulnerability in Python
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
python CWE-74
8.8
2017-12-14 CVE-2017-17521 Injection vulnerability in Fontforge
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.
network
low complexity
fontforge CWE-74
8.8
2017-12-14 CVE-2017-17520 Injection vulnerability in Debian TIN 2.4.1
tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
debian CWE-74
8.8
2017-12-14 CVE-2017-17519 Injection vulnerability in Ocaml Batteries Project Ocaml Batteries 2.6
batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
ocaml-batteries-project CWE-74
8.8
2017-12-14 CVE-2017-17518 Injection vulnerability in White Dune Project White Dune 0.30.10
swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
white-dune-project CWE-74
8.8
2017-12-14 CVE-2017-17517 Injection vulnerability in Sylpheed Project Sylpheed
libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
sylpheed-project CWE-74
8.8
2017-12-14 CVE-2017-17516 Injection vulnerability in Reddit Terminal Viewer Project Reddit Terminal Viewer 1.19.0
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
reddit-terminal-viewer-project CWE-74
8.8
2017-12-14 CVE-2017-17515 Injection vulnerability in multiple products
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
ecmwf debian CWE-74
8.8