Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
I2 Ibase MEDIUM 6.5
CVE-2020-4623

IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. …

Patch available
Fix from $1,600 2021-07-26
Supportassist For Business Pcs HIGH 7.8
CVE-2020-5316

Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.…

Patch available
Fix from $1,950 2021-07-22
Gpu Display Driver HIGH 7.8
CVE-2021-1089

NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execut…

Fix: 427.48 / 453.10+
Fix from $1,950 2021-07-22
Pcmanager HIGH 7.8
CVE-2021-3550

A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.

Fix: 3.0.500.5102+
Fix from $1,950 2021-07-16
Bat HIGH 7.8
CVE-2021-36753

sharkdp BAT before 0.18.2 executes less.exe from the current working directory.

Fix: 0.18.2+
Fix from $1,950 2021-07-15
Client Connector HIGH 7.8
CVE-2020-11634

The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adv…

Fix: 2.1.2.105+
Fix from $1,950 2021-07-15
Cortex Xdr Agent HIGH 7.8
CVE-2021-3042

A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated …

Mitigation only
Fix from $1,950 2021-07-15
Raon K Editor HIGH 7.8
CVE-2020-29157

An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted.

No fix yet
Fix from $1,950 2021-07-14
Thinapp HIGH 7.8
CVE-2021-22000

VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administ…

Fix: 5.2.10+
Fix from $1,950 2021-07-13
Endpoint Security MEDIUM 6.7
CVE-2021-35957

Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the…

Fix: after 2.0.2
Fix from $1,600 2021-07-13
Delta HIGH 7.8
CVE-2021-36376

dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.

Fix: 0.8.3+
Fix from $1,950 2021-07-13
Connect HIGH 7.8
CVE-2021-3613

OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, whi…

Fix: after 3.3.0
Fix from $1,950 2021-07-02
Openvpn HIGH 7.8
CVE-2021-3606

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present,…

Fix: 2.5.3+
Fix from $1,950 2021-07-02
After Effects HIGH 8.6
CVE-2021-28570

Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could ex…

Fix: after 18.1
Fix from $1,950 2021-06-28
Thunderbird HIGH 7.8
CVE-2021-29949

When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that is…

Fix: 78.9.1+
Fix from $1,950 2021-06-24
App Volumes HIGH 7.8
CVE-2021-21999

VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.1…

Fix: 2.18.10 / 11.2.6+
Fix from $1,950 2021-06-23
Anyconnect Secure Mobility Client MEDIUM 6.7
CVE-2021-1567

A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to p…

Fix: 4.10.01075+
Fix from $1,600 2021-06-16
Teamviewer HIGH 7.8
CVE-2021-34803

TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

Fix: 9.0.259145 / 10.0.259144+
Fix from $1,950 2021-06-16
Mcafee Agent HIGH 7.3
CVE-2021-31840

A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticate…

Fix: 5.7.3+
Fix from $1,950 2021-06-10
Big Ip Access Policy Manager HIGH 7.8
CVE-2021-23023

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Cli…

Fix: 7.2.1.3+
Fix from $1,950 2021-06-10
Cortex Xdr Agent HIGH 7.8
CVE-2021-3041

A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local…

Fix: 5.0.11 / 6.1.8+
Fix from $1,950 2021-06-10
Lapbc510 Firmware HIGH 7.8
CVE-2021-0057

Uncontrolled search path in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potent…

Fix: 1.1+
Fix from $1,950 2021-06-09
Driver \& Support Assistant HIGH 7.3
CVE-2021-0090

Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of pri…

Fix: 20.11.50.9+
Fix from $1,950 2021-06-09
Rapid Storage Technology HIGH 7.8
CVE-2021-0104

Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.…

Fix: 17.9.1.1009.5 / 18.0.3.1148.4+
Fix from $1,950 2021-06-09
Unite HIGH 7.3
CVE-2021-0108

Uncontrolled search path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an e…

Fix: 4.2.25031+
Fix from $1,950 2021-06-09
Processor Diagnostic Tool HIGH 7.3
CVE-2020-8702

Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially ena…

Fix: 4.1.5.37+
Fix from $1,950 2021-06-09
Webex Meetings Desktop HIGH 7.8
CVE-2021-1536

A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and C…

Mitigation only
Fix from $1,950 2021-06-04
Db2 HIGH 7.8
CVE-2019-4588

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code …

Mitigation only
Fix from $1,950 2021-05-26
Overwolf HIGH 7.8
CVE-2021-20726

Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary co…

Fix: after 2.168.0.n
Fix from $1,950 2021-05-24
Scansnap Manager HIGH 7.8
CVE-2021-20722

Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinS…

Fix: 7.0l20+
Fix from $1,950 2021-05-24