Vulnerabilities > GNU > Global > High

DATE CVE VULNERABILITY TITLE RISK
2017-12-14 CVE-2017-17531 Injection vulnerability in GNU Global 4.8.6
gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
network
low complexity
gnu CWE-74
8.8