{"id":"CVE-2017-17521","details":"uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.","modified":"2026-07-08T11:49:24.395790Z","published":"2017-12-14T16:29:00.683Z","related":["SUSE-SU-2025:1199-1","openSUSE-SU-2025:14981-1"],"references":[{"type":"REPORT","url":"https://security-tracker.debian.org/tracker/CVE-2017-17521"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fontforge/fontforge","events":[{"introduced":"0"},{"last_affected":"b9149c13e8f9464fc21473f1f676b36a2130775d"}],"database_specific":{"cpe":"cpe:2.3:a:fontforge:fontforge:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"20170731"}],"source":"CPE_RANGE"}}],"versions":["20170731","20170730","20161012","20161005","20161004","20161001","20160930","20150330","20160404","20160403","20150824","20150612","20150430","20150228","v2.1.0","20141230","20141126","20141014","20141013","2.0.20140101","v20120731-b","v20110222"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-17521.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}