Vulnerability index

Browse CVEs

1,200 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Forticlient HIGH 7.8
CVE-2019-6692

A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code exec…

Fix: after 6.2.0
Fix from $1,950 2019-10-24
Antivirus HIGH 7.8
CVE-2019-17093

An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %W…

Fix: 19.8+
Fix from $1,950 2019-10-23
Anti Threat Toolkit HIGH 7.8
CVE-2019-9491EPSS 13%

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the…

Fix: after 1.62.0.1218
Fix from $1,950 2019-10-21
Ghidra HIGH 7.8
CVE-2019-17665

NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.

Fix: after 9.0.2
Fix from $1,950 2019-10-16
Touchpoint Analytics MEDIUM 6.7
CVE-2019-6333

A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerabili…

Fix: 4.1.4.2827+
Fix from $1,600 2019-10-11
Encryption HIGH 7.3
CVE-2019-3745

The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise ver…

Fix: 2.4.0 / 10.4.0+
Fix from $1,950 2019-10-07
Resharper HIGH 7.3
CVE-2019-16407

JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.

Fix: 2019.2+
Fix from $1,950 2019-10-02
Update Package Framework MEDIUM 6.7
CVE-2019-3726

An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and …

Fix: 3.8.3.67 / 19.1.0.413+
Fix from $1,600 2019-09-24
Application Manager HIGH 7.8
CVE-2019-8076

Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead t…

Mitigation only
Fix from $1,950 2019-09-12
Omr HIGH 7.8
CVE-2019-11773

Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

Fix: 0.1+
Fix from $1,950 2019-09-12
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4447

IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary w…

Patch available
Fix from $1,950 2019-08-26
Design Review HIGH 7.8
CVE-2019-7362

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF…

Patch available
Fix from $1,950 2019-08-23
Advance Steel HIGH 7.8
CVE-2019-7364

DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, …

Patch available
Fix from $1,950 2019-08-23
Antivirus \+ Security 2019 HIGH 7.8
CVE-2019-14686

A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone …

Mitigation only
Fix from $1,950 2019-08-21
Password Manager HIGH 7.8
CVE-2019-14684

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigne…

No fix yet
Fix from $1,950 2019-08-20
Password Manager HIGH 7.8
CVE-2019-14687

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigne…

Mitigation only
Fix from $1,950 2019-08-20
Insightappsec HIGH 7.8
CVE-2019-5631

The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user …

Fix: after 2019.06.24
Fix from $1,950 2019-08-19
Character Animator HIGH 7.8
CVE-2019-7870

Adobe Character Animator versions 2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead …

Fix: after 2.1
Fix from $1,950 2019-08-14
Premiere Pro Cc HIGH 7.8
CVE-2019-7931

Adobe Premiere Pro CC versions 13.1.2 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead …

Fix: after 13.1.2
Fix from $1,950 2019-08-14
Prelude Cc HIGH 7.8
CVE-2019-7961

Adobe Prelude CC versions 8.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbit…

Fix: after 8.1
Fix from $1,950 2019-08-14
After Effects HIGH 7.8
CVE-2019-8062

Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arb…

Fix: after 16
Fix from $1,950 2019-08-14
Java HIGH 7.8
CVE-2019-4473

Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code inject…

Mitigation only
Fix from $1,950 2019-08-05
Antivirus Plus MEDIUM 6.7
CVE-2019-14242

An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antiviru…

Fix: 6.6.8.115 / 23.0.24.120+
Fix from $1,600 2019-07-30
Rufus HIGH 7.8
CVE-2019-1010100

Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privileg…

Fix: after 3.0
Fix from $1,950 2019-07-19
Dreamweaver HIGH 7.8
CVE-2019-7956

Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. S…

Fix: after 19.0
Fix from $1,950 2019-07-18
Proclima HIGH 7.8
CVE-2019-6825

A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL …

Fix: 8.0.0+
Fix from $1,950 2019-07-15
Insight Agent HIGH 7.8
CVE-2019-5629

Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when I…

Fix: after 2.6.3
Fix from $1,950 2019-07-13
Private Internet Access Vpn Client HIGH 7.8
CVE-2019-12575

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run …

No fix yet
Fix from $1,950 2019-07-11
Jabber HIGH 7.3
CVE-2019-1855

A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker …

Fix: 12.6+
Fix from $1,950 2019-07-04
Curl HIGH 7.8
CVE-2019-5443

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 au…

Fix: after 8.0.17
Fix from $1,950 2019-07-02