CVE-2017-17530
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
14/12/2017
Last modified:
20/04/2025
Description
common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: this is disputed by a third party because no untrusted input can be used for the injection
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:geomview:geomview:1.9.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page