VYPR
High severity8.3NVD Advisory· Published May 24, 2017· Updated May 13, 2026

CVE-2017-2798

CVE-2017-2798

Description

An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can send or provide a malicious XLS file to trigger this vulnerability.

Affected products

2
  • cpe:2.3:a:marklogic:marklogic:8.0-6:*:*:*:*:*:*:*
  • Antenna House/DMC HTMLFilterv5
    Range: as shipped with Marklogic 8.0-6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.