Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-42724 Critical, 799 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2020-15722

Published Jul 21, 2020

In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit D…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12423

Published Jul 9, 2020

When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leadin…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9100

Published Jul 6, 2020

Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to lo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3613

Published Jun 10, 2020

DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9858

Published Jun 9, 2020

A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Running the installer in an untru…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5357

Published May 28, 2020

Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the…

CVSS 7.1 · High

CVE-2020-13110

Published May 16, 2020

The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10616

Published May 14, 2020

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6244

Published May 12, 2020

SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be execu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20781

Published Apr 29, 2020

An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8895

Published Apr 21, 2020

Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthentica…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20780

Published Apr 17, 2020

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20769

Published Apr 17, 2020

An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8146

Published Apr 1, 2020

In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed b…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,001-1,025 of 1,188 CVEsPage 41 of 48