Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Mids\' Reborn Hero Designer HIGH 7.8
CVE-2020-11613

Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation…

No fix yet
Fix from $1,950 2020-06-11
Simatic Pcs 7 HIGH 7.8
CVE-2020-7585

A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All …

Fix: 5.4 / 5.6+
Fix from $1,950 2020-06-10
Agent HIGH 7.3
CVE-2019-3613

DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via executi…

Fix: 5.0.6 / 5.5.4+
Fix from $1,950 2020-06-10
Windows Migration Assistant HIGH 7.8
CVE-2020-9858

A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Run…

Fix: 2.2.0.0+
Fix from $1,950 2020-06-09
Dock Wd15 Firmware MEDIUM 6.0
CVE-2020-5357

Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The v…

Fix: 1.0.4 / 1.0.8+
Fix from $1,600 2020-05-28
Kerberos HIGH 7.8
CVE-2020-13110

The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of…

Fix: 1.0.0+
Fix from $1,950 2020-05-16
Softpac Project HIGH 8.8
CVE-2020-10616

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace …

Fix: after 9.6
Fix from $1,950 2020-05-14
Jserialcomm HIGH 7.8
CVE-2020-10626

In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same na…

Fix: after 2.2.2
Fix from $1,950 2020-05-14
Business Client HIGH 7.8
CVE-2020-6244

SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted…

Mitigation only
Fix from $1,950 2020-05-12
Bridge HIGH 7.8
CVE-2019-20781

An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.

Fix: 2019-04+
Fix from $1,950 2020-04-29
Media Server HIGH 7.8
CVE-2020-5740

Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privi…

Fix: 1.19.1.2701+
Fix from $1,950 2020-04-22
Earth HIGH 7.8
CVE-2020-8895

Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local…

Fix: 7.3.3+
Fix from $1,950 2020-04-21
Android CRITICAL 9.8
CVE-2019-20780

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether pack…

Mitigation only
Fix from $2,300 2020-04-17
Pc Suite HIGH 7.8
CVE-2019-20769

An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in…

Fix: after 5.3.27
Fix from $1,950 2020-04-17
Unified Communication \& Collaboration Client CRITICAL 9.8
CVE-2020-10515

STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.

Fix: 6.7.1.204+
Fix from $2,300 2020-04-02
Unifi Video HIGH 7.8
CVE-2020-8146

In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerab…

Fix: after 3.10.2
Fix from $1,950 2020-04-01
Acrobat Dc HIGH 7.8
CVE-2020-3803

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and…

Fix: 15.006.30518 / 17.011.30166+
Fix from $1,950 2020-03-25
Device Activation HIGH 7.8
CVE-2020-10649

DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional rest…

Fix: 1.0.7.0+
Fix from $1,950 2020-03-25
Pmepxm0100 Prosoft Configurator HIGH 7.8
CVE-2020-7474

A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which cou…

Fix: after 1.002
Fix from $1,950 2020-03-23
Forticlient Emergency Management Server HIGH 7.8
CVE-2020-9287

An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in…

Fix: after 6.2.1
Fix from $1,950 2020-03-15
Forticlient HIGH 7.8
CVE-2020-9290

An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the dire…

Fix: after 6.2.3
Fix from $1,950 2020-03-15
Password Manager HIGH 7.8
CVE-2020-8469

Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged…

Mitigation only
Fix from $1,950 2020-03-12
Graphics Driver HIGH 7.8
CVE-2020-0565

Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation …

Fix: 26.20.100.7158+
Fix from $1,950 2020-03-12
Graphics Driver HIGH 7.8
CVE-2020-0515

Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107, 15.36.3…

Fix: 15.33.49.5100 / 15.36.38.5117+
Fix from $1,950 2020-03-12
Control Manager HIGH 7.0
CVE-2019-14688

Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hija…

Mitigation only
Fix from $1,950 2020-02-20
Vulnerability Protection HIGH 7.8
CVE-2020-8601

Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL fil…

Mitigation only
Fix from $1,950 2020-02-20
Anyconnect Secure Mobility Client MEDIUM 6.5
CVE-2020-3153 KEVEPSS 27%

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy…

Fix: 4.8.02042+
Fix from $1,600 2020-02-19
Sandiskssddashboardsetup.exe HIGH 7.8
CVE-2020-8959

Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.

Fix: 3.0.2.0+
Fix from $1,950 2020-02-19
Endpoint Protection HIGH 7.8
CVE-2020-5821

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,950 2020-02-11
Jira Server HIGH 7.8
CVE-2019-20400

The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environ…

Fix: 8.5.2 / 8.6.0+
Fix from $1,950 2020-02-06