CVE-2017-17946: Novosoft Handy Password
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
A buffer overflow in Handy Password 4.9.3 allows remote attackers to execute arbitrary code via a long "Title name" field in "mail box" data that is mishandled in an "Open from mail box" action.
Affected products
- Novosoft Handy Password: version 4.9.3 only
Published 2018-01-10. Last modified 2026-06-17.