Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

655 CVEs tagged with CWE-42624 Critical, 536 High, 81 Medium, 13 Low, 1 Unrated.

CVE-2020-13813

Published Jun 4, 2020

An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto36…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13812

Published Jun 4, 2020

An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4019

Published Jun 1, 2020

The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7490

Published Apr 22, 2020

A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8895

Published Apr 21, 2020

Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthentica…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7079

Published Apr 17, 2020

An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code execution through maliciously crafted DLL files.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0598

Published Apr 15, 2020

Uncontrolled search path in the installer for the Intel(R) Binary Configuration Tool for Windows, all versions, may allow an authenticated user to potentially enable escalation of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11507

Published Apr 6, 2020

An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9418

Published Mar 5, 2020

An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12580

Published Mar 2, 2020

An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the aff…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3494

Published Feb 12, 2020

A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user exec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3942

Published Feb 11, 2020

Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17099

Published Jan 27, 2020

An Untrusted Search Path vulnerability in EPSecurityService.exe as used in Bitdefender Endpoint Security Tools versions prior to 6.6.11.163 allows an attacker to load an arbitrary…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17100

Published Jan 27, 2020

An Untrusted Search Path vulnerability in bdserviceshost.exe as used in Bitdefender Total Security 2020 allows an attacker to execute arbitrary code. This issue does not affect: B…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2773

Published Jan 14, 2020

Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6593

Published Jan 8, 2020

A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6019

Published Dec 26, 2019

Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 655 CVEsPage 14 of 27