Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Mcafee Agent HIGH 7.8
CVE-2020-7312

DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary cod…

Fix: 5.6.6+
Fix from $1,950 2020-09-10
Bundler HIGH 7.8
CVE-2019-3881

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the use…

Fix: 2.1.0+
Fix from $1,950 2020-09-04
Speed Browser HIGH 7.8
CVE-2020-24158

360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core bro…

Mitigation only
Fix from $1,950 2020-09-03
Netease Youdao Dictionary HIGH 7.8
CVE-2020-24159

NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou N…

Mitigation only
Fix from $1,950 2020-09-03
Tim HIGH 7.8
CVE-2020-24160

Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.

Mitigation only
Fix from $1,950 2020-09-03
Netease Mail Master HIGH 7.8
CVE-2020-24161

Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious cod…

Mitigation only
Fix from $1,950 2020-09-03
Tencent HIGH 7.8
CVE-2020-24162

The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerabilit…

Mitigation only
Fix from $1,950 2020-09-03
Security Center HIGH 7.8
CVE-2020-25045

Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijackin…

Fix: 12+
Fix from $1,950 2020-09-02
Miller HIGH 8.6
CVE-2020-15167

In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to …

No fix yet
Fix from $1,950 2020-09-02
Rabbitmq Server MEDIUM 6.7
CVE-2020-5419

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code executio…

Fix: 3.7.28 / 3.8.7+
Fix from $1,600 2020-08-31
PostgreSQL HIGH 7.1
CVE-2020-14349

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication.…

Fix: 10.14 / 11.9+
Fix from $1,950 2020-08-24
Lightroom HIGH 7.8
CVE-2020-9724

Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation could lead to privilege escalat…

Fix: after 9.2.0.10
Fix from $1,950 2020-08-19
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2020-3433 KEVEPSS 10%

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, …

Fix: 4.9.00086+
Fix from $1,950 2020-08-17
Sharing Service HIGH 7.8
CVE-2020-9767

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine…

Mitigation only
Fix from $1,950 2020-08-14
Smartcontrol HIGH 7.3
CVE-2020-7360

An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an a…

Fix: after 4.3.15
Fix from $1,950 2020-08-13
Rste Software Raid HIGH 7.8
CVE-2020-8687

Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 ma…

Fix: 4.7.0.1119+
Fix from $1,950 2020-08-13
Elite X2 1012 G1 Firmware MEDIUM 6.7
CVE-2020-15596

The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure …

Fix: 8.2206.1717.166 / 8.2206.1717.634+
Fix from $1,600 2020-08-12
Graphics Agent HIGH 7.8
CVE-2020-13177

The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use ha…

Fix: 20.04.1+
Fix from $1,950 2020-08-11
Firefox HIGH 7.8
CVE-2020-15657

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placi…

Fix: 78.1 / 79.0+
Fix from $1,950 2020-08-10
Seafile Client HIGH 7.8
CVE-2020-16143

The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.

No fix yet
Fix from $1,950 2020-07-29
Pi Api HIGH 7.8
CVE-2020-10610

In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System s…

Fix: after 4.8.0.18
Fix from $1,950 2020-07-24
360 Total Security HIGH 7.8
CVE-2020-15722

In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. A…

Fix: after 12.1.0.1004
Fix from $1,950 2020-07-21
360 Total Security HIGH 7.8
CVE-2020-15723

In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local pr…

Fix: after 12.1.0.1004
Fix from $1,950 2020-07-21
360 Total Security HIGH 7.8
CVE-2020-15724

In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulner…

Fix: after 12.1.0.1005
Fix from $1,950 2020-07-21
Firefox HIGH 7.8
CVE-2020-12423

When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox m…

Fix: 78.0+
Fix from $1,950 2020-07-09
Hisuite HIGH 7.8
CVE-2020-9100

Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. A…

Fix: 10.1.0.500+
Fix from $1,950 2020-07-06
Python HIGH 7.8
CVE-2020-15523

In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used i…

Fix: 3.5.10 / 3.6.12+
Fix from $1,950 2020-07-04
Jira Data Center HIGH 7.8
CVE-2019-20419

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomc…

Fix: 8.5.5 / 8.7.2+
Fix from $1,950 2020-07-03
Gitlab Vscode Extension HIGH 8.6
CVE-2020-13279

Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system

Fix: after 2.2.0
Fix from $1,950 2020-06-22
Mattermost Desktop CRITICAL 9.8
CVE-2019-20856

An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.

Fix: 4.3.0+
Fix from $2,300 2020-06-19