Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,189 CVEs tagged with CWE-42724 Critical, 800 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2021-3633

Published Aug 17, 2021

A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0160

Published Aug 11, 2021

Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable es…

CVSS 7.8 · High

CVE-2021-32580

Published Aug 5, 2021

Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1593

Published Aug 4, 2021

A vulnerability in Cisco Packet Tracer for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerabil…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-18173

Published Jul 26, 2021

A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4623

Published Jul 26, 2021

IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. By using a specially-crafted .…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1089

Published Jul 22, 2021

NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execution, denial of service, inform…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3550

Published Jul 16, 2021

A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36753

Published Jul 15, 2021

sharkdp BAT before 0.18.2 executes less.exe from the current working directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11634

Published Jul 15, 2021

The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29157

Published Jul 14, 2021

An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22000

Published Jul 13, 2021

VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administrative privileges may exploit…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-35957

Published Jul 13, 2021

Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3613

Published Jul 2, 2021

OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3606

Published Jul 2, 2021

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28570

Published Jun 28, 2021

Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29949

Published Jun 24, 2021

When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distributed by Thunderbird…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 851-875 of 1,189 CVEsPage 35 of 48