Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cjh-6cvj-78v9

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and worldgui.c.

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and worldgui.c.

EPSS

Процентиль: 68%
0.0056
Низкий

8.8 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and worldgui.c.

CVSS3: 8.8
nvd
около 8 лет назад

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and worldgui.c.

CVSS3: 8.8
debian
около 8 лет назад

KildClient 3.1.0 does not validate strings before launching the progra ...

EPSS

Процентиль: 68%
0.0056
Низкий

8.8 High

CVSS3

Дефекты

CWE-74