Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

655 CVEs tagged with CWE-42624 Critical, 536 High, 81 Medium, 13 Low, 1 Unrated.

CVE-2019-19929

Published Dec 23, 2019

An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded b…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18996

Published Dec 18, 2019

Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker w…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8801

Published Dec 18, 2019

A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14599

Published Dec 16, 2019

Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17446

Published Nov 22, 2019

An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be used to start external programs with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6189

Published Nov 20, 2019

A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16861

Published Nov 19, 2019

Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could create or modify a dynamic-lin…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16860

Published Nov 19, 2019

Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynam…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18196

Published Oct 24, 2019

A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.2.36215 (fixed in 1…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17664

Published Oct 16, 2019

NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when laun…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17449

Published Oct 10, 2019

Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least…

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-14960

Published Oct 1, 2019

JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13357

Published Sep 24, 2019

In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6826

Published Sep 17, 2019

A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVA…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11660

Published Sep 13, 2019

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3646

Published Sep 13, 2019

DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Trial 16.0.R18 and earlier allows local users to execute arbit…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15295

Published Aug 21, 2019

An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, a…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-5631

Published Aug 19, 2019

The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must alread…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10837

Published Aug 1, 2019

cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 655 CVEsPage 15 of 27