Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

655 CVEs tagged with CWE-42624 Critical, 536 High, 81 Medium, 13 Low, 1 Unrated.

CVE-2020-5144

Published Oct 28, 2020

SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6023

Published Oct 27, 2020

Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5977

Published Oct 23, 2020

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8338

Published Oct 14, 2020

A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10733

Published Sep 16, 2020

The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0570

Published Sep 14, 2020

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-7315

Published Sep 10, 2020

DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4545

Published Sep 4, 2020

IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By pers…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10610

Published Jul 24, 2020

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the…

CVSS 7.8 · High

CVE-2020-8317

Published Jul 24, 2020

A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privi…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15009

Published Jul 20, 2020

AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9673

Published Jul 17, 2020

Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9672

Published Jul 17, 2020

Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1458

Published Jul 14, 2020

A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Ex…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-11081

Published Jul 10, 2020

osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user m…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3768

Published Jun 26, 2020

ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-7279

Published Jun 10, 2020

DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS) for Windows prior to 8.0.0 Patch 15 Update allows attacke…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6196

Published Jun 9, 2020

A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6173

Published Jun 9, 2020

A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has adm…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21241

Published Jun 4, 2020

An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allows a DLL to execute remote code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 655 CVEsPage 13 of 27