VYPR
High severity8.3NVD Advisory· Published May 23, 2017· Updated May 13, 2026

CVE-2017-2793

CVE-2017-2793

Description

An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious XLS file to trigger this vulnerability.

Affected products

2
  • cpe:2.3:a:marklogic:marklogic:8.0-6:*:*:*:*:*:*:*
  • Antenna House/DMC HTMLFilterv5
    Range: as shipped with MarkLogic 8.0-6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.