Skip to main content

CWE archive

CWE-426 CVEs

Programmatic archive

655 CVEs tagged with CWE-42624 Critical, 536 High, 81 Medium, 13 Low, 1 Unrated.

CVE-2018-0648

Published Sep 7, 2018

Untrusted search path vulnerability in installer of ChatWork Desktop App for Windows 2.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecifi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0656

Published Sep 4, 2018

Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5003

Published Aug 29, 2018

Adobe Creative Cloud Desktop Application before 4.5.5.342 (installer) has an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0621

Published Jul 26, 2018

Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified d…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0620

Published Jul 26, 2018

Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0619

Published Jul 26, 2018

Untrusted search path vulnerability in the installer of Glarysoft Glary Utilities (Glary Utilities 5.99 and earlier and Glary Utilities Pro 5.99 and earlier) allows an attacker to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10875

Published Jul 13, 2018

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an atta…

CVSS 7.8 · High

CVE-2018-13133

Published Jul 4, 2018

Golden Frog VyprVPN before 2018-06-21 has a vulnerability associated with the installation process on Windows.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12589

Published Jun 28, 2018

Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0609

Published Jun 26, 2018

Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0601

Published Jun 26, 2018

Untrusted search path vulnerability in axpdfium v0.01 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0600

Published Jun 26, 2018

Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an uns…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0599

Published Jun 26, 2018

Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0598

Published Jun 26, 2018

Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows allows an attacker to gain privileges via a Trojan horse DL…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0597

Published Jun 26, 2018

Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0596

Published Jun 26, 2018

Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0595

Published Jun 26, 2018

Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 655 CVEsPage 18 of 27