Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

655 CVEs tagged with CWE-42624 Critical, 536 High, 81 Medium, 13 Low, 1 Unrated.

CVE-2011-4125

Published Oct 27, 2021

A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26557

Published Oct 7, 2021

When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36297

Published Sep 28, 2021

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31841

Published Sep 22, 2021

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name a…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41387

Published Sep 17, 2021

seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37617

Published Aug 18, 2021

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21562

Published Aug 3, 2021

Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_U…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25699

Published Jul 21, 2021

The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25698

Published Jul 21, 2021

The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26807

Published Apr 30, 2021

GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29221

Published Apr 9, 2021

A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's directory, a local attacker could hi…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28249

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-28246

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4739

Published Nov 20, 2020

IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authentic…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6014

Published Nov 2, 2020

Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 655 CVEsPage 12 of 27