Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-42724 Critical, 799 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2020-7358

Published Sep 18, 2020

In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the lo…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7312

Published Sep 10, 2020

DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3881

Published Sep 4, 2020

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not ava…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24162

Published Sep 3, 2020

The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24161

Published Sep 3, 2020

Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24160

Published Sep 3, 2020

Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24159

Published Sep 3, 2020

NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24158

Published Sep 3, 2020

360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Te…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15167

Published Sep 2, 2020

In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9724

Published Aug 19, 2020

Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation could lead to privilege escalation.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-3433

Published Aug 17, 2020

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DL…

CVSS 7.8 · High
evidence mentions
4
Buzz score
52.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-9767

Published Aug 14, 2020

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was runn…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7360

Published Aug 13, 2020

An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an authenticated user to escalate…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8687

Published Aug 13, 2020

Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16143

Published Jul 29, 2020

The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10610

Published Jul 24, 2020

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the…

CVSS 7.8 · High

CVE-2020-15724

Published Jul 21, 2020

In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15723

Published Jul 21, 2020

In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerabili…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 1,188 CVEsPage 40 of 48