ZeroHour

CVE-2017-17534

CVSS 3.0
8.8 high
EPSS
1%p67
Published
()
Modified
Description

uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17521.

Vendors
mensis project
Products
mensis
Weakness
CWE-74
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.