605
VMScore

CVE-2017-17514

Published: 14/12/2017 Updated: 11/04/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote malicious users to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable

Vulnerable Product Search on Vulmon Subscribe to Product

nip2 project nip2 8.4.0

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

debian debian linux 10.0