Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

669 CVEs tagged with CWE-42625 Critical, 544 High, 85 Medium, 14 Low, 1 Unrated.

CVE-2019-18196

Published Oct 24, 2019

A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.2.36215 (fixed in 1…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17664

Published Oct 16, 2019

NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when laun…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17449

Published Oct 10, 2019

Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least…

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-14960

Published Oct 1, 2019

JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13357

Published Sep 24, 2019

In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6826

Published Sep 17, 2019

A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVA…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11660

Published Sep 13, 2019

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3646

Published Sep 13, 2019

DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Trial 16.0.R18 and earlier allows local users to execute arbit…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15295

Published Aug 21, 2019

An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, a…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-5631

Published Aug 19, 2019

The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must alread…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10837

Published Aug 1, 2019

cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9492

Published Jul 26, 2019

A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disab…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1010100

Published Jul 19, 2019

Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executabl…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13637

Published Jul 17, 2019

In LogMeIn join.me before 3.16.0.5505, an attacker could execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12912

Published Jul 17, 2019

Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12569

Published Jun 3, 2019

A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5589

Published May 28, 2019

An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16156

Published May 17, 2019

In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 669 CVEsPage 16 of 27